CVE-2017-5677: PEAR Html AJAX
Critical severity, CVSS 9.8. EPSS: 4.8% chance of exploitation in the next 30 days.
PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect regular expression.
Affected products
- PEAR Html AJAX: version 0.3.0 only; version 0.3.1 only; version 0.3.2 only; version 0.3.3 only; version 0.3.4 only; version 0.4.0 only; …
Published 2017-02-06. Last modified 2026-06-17.