PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object...
Critical severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Description
Published by the National Vulnerability Database
Feb 6, 2017
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 2, 2023
PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect regular expression.
References