← Back

CVE-2020-7066

nvd nist
Published: Apr 1, 2020Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.

Affected (9)

Products: Php: Php · Tenable: Tenable.sc · Opensuse: Leap · +1 more
Show all products
1 product
Php
1 product
Tenable.sc
1 product
Leap
1 product
Debian Linux
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Php
From 7.2.0 to 7.2.29
From 7.3.0 to 7.3.16
From 7.4.0 to 7.4.4
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Tenable
Before 5.19.0
Version 5.19.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.1
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 8.0
Version 9.0

References (16)

Source: security@php.net
ExploitIssue TrackingPatchVendor Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.