Back to Database
Status published
Critical
CVE-2017-5677
PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection...
Vulnerability Description
PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect regular expression.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-5677
Credits & Attribution
No credits recorded in the NVD database.
References
- http://karmainsecurity.com/KIS-2017-01
- http://blog.pear.php.net/2017/02/02/security-html_ajax-058/
- http://seclists.org/fulldisclosure/2017/Feb/12
- http://www.securityfocus.com/bid/96044
- https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f5acb5adcd195f9a06b732794cb0de7620def646
- https://pear.php.net/bugs/bug.php?id=21165
More from pear
View All →CVE-2022-24953
The Crypt_GPG extension before 1.6.7 for PHP does not prevent...
Medium
5.3
CVE-2009-4111
Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14,...
Medium
6.8
CVE-2009-4025
Argument injection vulnerability in the traceroute function in Traceroute.php in...
Critical
10
CVE-2009-4024
Argument injection vulnerability in the ping function in Ping.php in...
Critical
10
CVE-2009-4023
Argument injection vulnerability in the sendmail implementation of the Mail::Send...
High
7.5
Affected Vendor
pear
View all reports →Affected Software
html ajax
Vulnerable Versions:
0.3.0, 0.3.1, 0.3.2, 0.3.3, 0.3.4, 0.4.0, 0.4.1, 0.5.0, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.5, 0.5.6, 0.5.7
Timeline
Official Publish:
February 6th, 2017
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.