CVE Database
/

CVE-2015-6836

Back to search

CVE-2015-6836

Published: Jan 19, 2016

Modified: Aug 6, 2024

PUBLISHED

Description

The SoapClient __call method in ext/soap/soap.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 does not properly manage headers, which allows remote attackers to execute arbitrary code via crafted serialized data that triggers a "type confusion" in the serialize_function_call function.

VendorProductVersions

n/a

n/a

affected
n/a

References

1033548
vdb-entry
x_refsource_SECTRACK
76644
vdb-entry
x_refsource_BID
DSA-3358
vendor-advisory
x_refsource_DEBIAN
GLSA-201606-10
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2015-6836 - Security Vulnerability | QwikSec