CVE-2011-4885
PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
- Php
- ≤ 5.3.8, 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.1.1, 5.1.2, 5.1.3, 5.1.4, 5.1.5, 5.1.6, 5.2.0, 5.2.1, 5.2.2, 5.2.3, 5.2.4, 5.2.5, 5.2.6, 5.2.7, 5.2.8, 5.2.9, 5.2.10, 5.2.11, 5.2.12, 5.2.14, 5.2.15, 5.2.16, 5.2.17, 5.3.0, 5.3.1, 5.3.2, 5.3.3, 5.3.4, 5.3.5, 5.3.6, 5.3.7
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 83.9% (100th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2011-12-30
CVE-2011-4885 at NVD
16 known exploits for CVE-2011-4885
Proof-of-concept code and exploit modules indexed by Sploitus
Hashtable Collisions
PHP Hash Table Collision Proof Of Concept
PHP Hashtables Denial of Service
Hashtable Collisions
PHP "php_register_variable_ex()"函数任意代码执行漏洞(CVE-2012-0830)
PHP Hash Table Collision Proof Of Concept
PHP Hash Table Collision - Denial of Service (PoC)
PHP Hash Table Collision - Denial of Service (PoC)
PHP 5.3.x Hash Collision Proof Of Concept Code
PHP Hashtables Denial of Service
PHP 5.3.8 - Hashtables Denial of Service
PHP 5.3.8 - Hashtables Denial of Service
PHP 5.3.x Hashtables Proof Of Concept
PHP Web表单哈希冲突拒绝服务漏洞
Multiple Programming Language Implementations Vulnerable to Hash Table Collision Attacks
MyBulletinBoard (MyBB) 1.1.5 - 'CLIENT-IP' SQL Injection