{ "CVE_data_meta":{ "ASSIGNER":"cve@mitre.org", "ID":"CVE-2018-5712", "STATE":"PUBLIC" }, "affects":{ "vendor":{ "vendor_data":[ { "product":{ "product_data":[ { "product_name":"n/a", "version":{ "version_data":[ { "version_value":"n/a" } ] } } ] }, "vendor_name":"n/a" } ] } }, "data_format":"MITRE", "data_type":"CVE", "data_version":"4.0", "description":{ "description_data":[ { "lang":"eng", "value":"An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file." } ] }, "problemtype":{ "problemtype_data":[ { "description":[ { "lang":"eng", "value":"n/a" } ] } ] }, "references":{ "reference_data":[ { "name":"USN-3600-1", "refsource":"UBUNTU", "url":"https://usn.ubuntu.com/3600-1/" }, { "name":"1040363", "refsource":"SECTRACK", "url":"http://www.securitytracker.com/id/1040363" }, { "name":"104020", "refsource":"BID", "url":"http://www.securityfocus.com/bid/104020" }, { "name":"RHSA-2018:1296", "refsource":"REDHAT", "url":"https://access.redhat.com/errata/RHSA-2018:1296" }, { "name":"http://php.net/ChangeLog-5.php", "refsource":"CONFIRM", "url":"http://php.net/ChangeLog-5.php" }, { "name":"USN-3566-1", "refsource":"UBUNTU", "url":"https://usn.ubuntu.com/3566-1/" }, { "name":"http://php.net/ChangeLog-7.php", "refsource":"CONFIRM", "url":"http://php.net/ChangeLog-7.php" }, { "name":"[debian-lts-announce] 20180120 [SECURITY] [DLA 1251-1] php5 security update", "refsource":"MLIST", "url":"https://lists.debian.org/debian-lts-announce/2018/01/msg00025.html" }, { "name":"https://bugs.php.net/bug.php?id=74782", "refsource":"CONFIRM", "url":"https://bugs.php.net/bug.php?id=74782" }, { "name":"102742", "refsource":"BID", "url":"http://www.securityfocus.com/bid/102742" }, { "name":"USN-3600-2", "refsource":"UBUNTU", "url":"https://usn.ubuntu.com/3600-2/" }, { "refsource":"REDHAT", "name":"RHSA-2019:2519", "url":"https://access.redhat.com/errata/RHSA-2019:2519" }, { "url":"https://www.oracle.com/security-alerts/cpuapr2020.html" } ] } }