CVE-2010-0397

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/03/2010
Last modified:
11/04/2025

Description

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:php:php:5.3.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools