← Back

CVE-2015-5723

nvd nist
Published: Jun 7, 2016Modified: May 6, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.

Affected (25)

3 products
Zend Cache
Zend Framework
Zf Apigility Doctrine
1 product
Debian Linux
Object Relational Mapper
Doctrinemongodbbundle
Common
Annotations
Mongodb Odm
Cache
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Zend
Up to 2.4.7
Version 2.5.0
Version 2.5.1
Version 2.5.2
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 7.0
Version 8.0
Configuration C
7 vulnerable
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.0.0
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.4.7
Configuration F
3 vulnerable
Vulnerable SoftwareAffected Versions
Doctrine Project
Up to 2.4.2
Version 2.5.0
Version 2.5.0 beta1
Configuration G
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.2.6
Configuration H
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.0.1
Configuration I
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.12.15
Configuration J
3 vulnerable
Vulnerable SoftwareAffected Versions
Doctrine Project
Up to 1.3.1
Version 1.4.0
Version 1.4.1
Configuration K
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.0.2

Related CWEs

Timeline

No history available yet.