CVE-2010-2190 describes an information disclosure vulnerability affecting PHP versions 5.2 through 5.2.13 and 5.3 through 5.3.2. Specifically, the trim, ltrim, rtrim, and substr_replace functions can be manipulated to reveal sensitive memory contents due to an issue with the call time pass by reference feature. This vulnerability has a CVSS score of 5.0, indicating a medium severity, and allows unauthenticated attackers to remotely obtain sensitive information with low attack complexity. There is no evidence of active exploitation, nor are there public exploits available in Metasploit or ExploitDB. Community discussion and media coverage are minimal, suggesting low current attention to this decade-old vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2.0CPE matchmatch criteria | cpe:2.3:a:php:php:5.2.0:*:*:*:*:*:*:* | ||
5.2.1CPE matchmatch criteria | cpe:2.3:a:php:php:5.2.1:*:*:*:*:*:*:* | ||
5.2.2CPE matchmatch criteria | cpe:2.3:a:php:php:5.2.2:*:*:*:*:*:*:* | ||
5.2.3CPE matchmatch criteria | cpe:2.3:a:php:php:5.2.3:*:*:*:*:*:*:* | ||
5.2.4CPE matchmatch criteria | cpe:2.3:a:php:php:5.2.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.