Description
The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.
Remediation
References
Related Vulnerabilities
WordPress Plugin Database Backups Cross-Site Request Forgery (1.2.2.6)
Atlassian Confluence Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-22504)
Jboss EAP Generation of Error Message Containing Sensitive Information Vulnerability (CVE-2025-5731)
Opencart Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-13067)