HN user

newguy33

17 karma
Posts0
Comments4
View on HN
No posts found.

Critical is an overstatement but it userland PHP execution does not equate to native process control. There are many situations where an attacker may have constrained PHP execution, gadget execution, template or plugin execution, deserialization reachability, or a sandboxed context, but not arbitrary native code execution or arbitrary memory write. Definitely impactful

Yea, that's what's confusing. some of these are like lower level slop but some are like genuine criticals.

Floci, libssh2, c-ares, FFmpeg, and the PHP one are all LEGIT./

The Ghidra one for example, not so much. I cant help but wonder if this was halfway completed research folder and they just published it as is