← back
CVE-2012-3450

CVE-2012-3450

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 11%
from disclosure to weapon0 days
Published on NVDAug 6
1st PoCAug 2
exploitation probability
11%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.