← Back

CVE-2010-1868

nvd nist
Published: May 7, 2010Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

The (1) sqlite_single_query and (2) sqlite_array_query functions in ext/sqlite/sqlite.c in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to execute arbitrary code by calling these functions with an empty SQL query, which triggers access of uninitialized memory.

Affected (16)

Products: Php: Php
1 product
Php
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Php
Version 5.2.0
Version 5.2.10
Version 5.2.11
Version 5.2.12
Version 5.2.13
Version 5.2.1
Version 5.2.2
Version 5.2.3
Version 5.2.4
Version 5.2.5
Version 5.2.6
Version 5.2.8
Version 5.2.9
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Php
Version 5.3.0
Version 5.3.1
Version 5.3.2

Timeline

No history available yet.