peter bassill · operator
$ cve CVE-2012-3450 JSON

CVE-2012-3450 EXPLOIT

2.6
LOW · CVSS 2.0 · EPSS 11.2% (pctl 96)

Patch early

A public exploit exists.

Description

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.

Scoring

CVSS2.6 (LOW, v2.0)
VectorAV:N/AC:H/Au:N/C:N/I:N/A:P
EPSS11.18% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2012-08-06
Last modified2026-06-16

Affected (1)

VendorProduct
phpphp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD