CVE-2011-4885 describes a denial-of-service vulnerability in PHP versions prior to 5.3.9, where an attacker can exploit predictable hash collisions in form parameter processing. This allows remote attackers to consume excessive CPU resources by sending specially crafted parameters. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P), it is easily exploitable over the network with low complexity, leading to a partial availability impact. Exploit code is publicly available through Metasploit and ExploitDB, and the vulnerability has garnered significant community discussion and media coverage, indicating a high level of awareness and potential for exploitation, despite not being on the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.3.8CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
5.0.0CPE matchmatch criteria | cpe:2.3:a:php:php:5.0.0:*:*:*:*:*:*:* | ||
5.0.0CPE matchmatch criteria | cpe:2.3:a:php:php:5.0.0:beta1:*:*:*:*:*:* | ||
5.0.0CPE matchmatch criteria | cpe:2.3:a:php:php:5.0.0:beta2:*:*:*:*:*:* | ||
5.0.0CPE matchmatch criteria | cpe:2.3:a:php:php:5.0.0:beta3:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.