Critical Flaw in PHP’s extract() Function Enables Arbitrary Code Execution

Post Reply
Shane1145
Posts: 1624
Joined: Wed Sep 25, 2024 2:31 pm

Critical Flaw in PHP’s extract() Function Enables Arbitrary Code Execution

Post by Shane1145 »

A critical vulnerability in PHP’s extract() function has been uncovered, enabling attackers to execute arbitrary code by exploiting memory corruption flaws.

The issue affects PHP versions 5.x, 7.x, and 8.x, allowing malicious actors to trigger double-free (PHP 5.x) or use-after-free (PHP 7.x/8.x) conditions, ultimately leading to remote code execution (RCE).

https://gbhackers.com/critical-flaw-in- ... -function/
Post Reply