cvedb.io
CVE-2015-5723
HIGH · CVSS 7.8
EPSS exploitation probability: 0%
Published 2016-06-07T14:06:08.697 · Last modified 2026-06-17T00:29:39.550

Summary

Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.

Affected products

zend — zend-cache

Does this affect you?

Add your gear to cvedb and we'll alert you only when zend ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.