Description
Integer overflow in the str_replace function in PHP 4.4.5 and PHP 5.2.1 allows context-dependent attackers to have an unknown impact via a single character search string in conjunction with a single character replacement string, which causes an "off by one overflow."
Remediation
References
Related Vulnerabilities
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-3662)
WordPress Plugin Instinct e-Commerce Arbitrary File Upload (3.4)
WordPress Plugin WP Security Safe Cross-Site Request Forgery (2.2.2)
WordPress Plugin Secure HTML5 Video Player Cross-Site Scripting (3.14)
WordPress Plugin Stockists Manager for Woocommerce Cross-Site Request Forgery (1.0.2.1)