CVE
- Id
- 104092
- CVE No.
- CVE-2017-7272
- Status
- Candidate
- Description
- PHP through 7.1.3 enables potential SSRF in applications that accept an fsockopen hostname argument with an expectation that the port number is constrained. Because a :port syntax is recognized, fsockopen will use the port number that is specified in the hostname argument, instead of the port number in the second argument of the function.
- Phase
- Assigned (20170327)
- Votes
- None (candidate not yet proposed)
- Comments