CVE-2015-5243
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
20/08/2018
Last modified:
26/06/2019
Description
phpWhois allows remote attackers to execute arbitrary code via a crafted whois record.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:phpwhois_project:phpwhois:*:*:*:*:*:*:*:* | 4.2.2 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://blog.nettitude.com/uk/cve-2015-5243-phpwhois-remote-code-execution
- https://github.com/Gemorroj/phpwhois/commit/91c937e03c876ba1290b6de2a3ad953d2105fdd0
- https://github.com/jsmitty12/phpWhois/blob/master/CHANGELOG.md
- https://github.com/jsmitty12/phpWhois/issues/19
- https://github.com/sbaresearch/advisories/tree/public/2018/SBA-ADV-20180425-01_phpWhois_Code_Execution
- https://github.com/sparc/phpWhois.org/commit/5cc572490c9053d46598ec9348a11e36a5a33a46#diff-f150ae17da7341bf6c2eff928684b3a3



