CVE-2016-3185 is a type confusion vulnerability affecting PHP versions before 5.4.44, 5.5.28, 5.6.12, and 7.0.4. It resides in the make_http_soap_request function within the SOAP extension, specifically when handling crafted serialized _cookies data via the SoapClient::__call method. This vulnerability carries a CVSS v3 score of 7.1 (High), indicating that a low-privilege local attacker can achieve high confidentiality impact by obtaining sensitive information from process memory or cause a high availability impact through a denial of service (application crash). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.6.0CPE matchmatch criteria | cpe:2.3:a:php:php:5.6.0:alpha1:*:*:*:*:*:* | ||
5.6.0CPE matchmatch criteria | cpe:2.3:a:php:php:5.6.0:alpha2:*:*:*:*:*:* | ||
5.6.0CPE matchmatch criteria | cpe:2.3:a:php:php:5.6.0:alpha3:*:*:*:*:*:* | ||
5.6.0CPE matchmatch criteria | cpe:2.3:a:php:php:5.6.0:alpha4:*:*:*:*:*:* | ||
5.6.0CPE matchmatch criteria | cpe:2.3:a:php:php:5.6.0:alpha5:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.