bugs.launchpad.netConfirmation
https://bugs.launchpad.net/php-gettext/+bug/1606184 CVE-2016-6175
CRITICAL
PHP gettext 1.0.12 - 'gettext.php' Code Execution
Record summary
CVE-2016-6175 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPHP gettext 1.0.12 - 'gettext.php' Code ExecutionExploitDB exploitby kmkzNot analyzed1 file
References
5github.comConfirmation
https://github.com/NagVis/nagvis/commit/4fe8672a5aec3467da72b5852ca6d283c15adb53 kmkz-web-blog.blogspot.cz
https://kmkz-web-blog.blogspot.cz/2016/07/advisory-cve-2016-6175.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-6175 40154exploit
https://www.exploit-db.com/exploits/40154