CVE-2017-5358 describes stack-based buffer overflows in php_Easycom5_3_0.dll, affecting EasyCom for PHP 4.0.0.29 and easycom-aura. This critical vulnerability (CVSS 9.8) allows unauthenticated remote attackers to execute arbitrary code by supplying a malicious server argument to i5_connect, i5_pconnect, or i5_private_connect API functions. While not actively exploited in the wild (no KEV entry), a Proof-of-Concept exploit is publicly available on ExploitDB, and the vulnerability has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.0.29CPE matchmatch criteria | cpe:2.3:a:easycom-aura:easycom_for_php:4.0.0.29:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.