|
php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login |
PatchesPull RequestsHistoryAllCommentsChangesGit/SVN commits
[2017-11-09 16:00 UTC] johannes@php.net
-Status: Open
+Status: Duplicate
[2017-11-09 16:00 UTC] johannes@php.net
[2018-01-15 13:31 UTC] kaplan@php.net
-CVE-ID:
+CVE-ID: 2017-7272
[2018-02-28 22:13 UTC] contacto at agora-security dot com
|
|||||||||||||||||||||||||||
Copyright © 2001-2025 The PHP GroupAll rights reserved. |
Last updated: Fri Oct 24 06:00:01 2025 UTC |
Description: ------------ This bug is related to bug#74216,but they are not the same function.It may cause ssrf vulnerability in Web Application. Test script: --------------- <?php $fp = pfsockopen("192.168.75.183:8000", 443); Expected result: ---------------- It will accept from 443. Actual result: -------------- hjy@ubuntu:~$ nc -lvv 8000 Listening on [0.0.0.0] (family 0, port 8000) Connection from [192.168.75.183] port 8000 [tcp/*] accepted (family 2, sport 53352)