← Back

CVE-2010-1860

nvd nist
Published: May 7, 2010Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The html_entity_decode function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal call, related to the call time pass by reference feature.

Affected (16)

Products: Php: Php
1 product
Php
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Php
Version 5.2.0
Version 5.2.10
Version 5.2.11
Version 5.2.12
Version 5.2.13
Version 5.2.1
Version 5.2.2
Version 5.2.3
Version 5.2.4
Version 5.2.5
Version 5.2.6
Version 5.2.8
Version 5.2.9
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Php
Version 5.3.0
Version 5.3.1
Version 5.3.2

Timeline

No history available yet.