← לוח פגיעויות

CVE-2000-0967

טרם דורגה

טרם דורג — בהתאם למדיניות NVD מאפריל 2026, רוב ה-CVE אינם מנותחים מיידית. ציון EPSS (אם קיים) עדיין מוצג.

תיאור (מקור, אנגלית)

PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.

מדדים

מוצרים מושפעים

php: php

קישורים