Description
An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file.
Remediation
References
Related Vulnerabilities
Ruby Cryptographic Issues Vulnerability (CVE-2011-2686)
Mailman Other Vulnerability (CVE-2002-0855)
WordPress Plugin Ninja Announcements Lite 'ninja_annc.php' SQL Injection (1.2.3)
WordPress 2.8.2 Multiple Security Bypass Vulnerabilities (2.0 - 2.8.2)
Roundcube Multiple Cross-site Request Forgery (CSRF) Vulnerabilities (CVE-2014-9587)