Critical severity9.8NVD Advisory· Published Aug 20, 2018· Updated Jun 17, 2026
CVE-2015-5243
CVE-2015-5243
Description
phpWhois allows remote attackers to execute arbitrary code via a crafted whois record.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
jsmitty12/phpwhoisPackagist | < 5.1.0 | 5.1.0 |
phpwhois/phpwhoisPackagist | <= 4.2.5 | — |
brightlocal/phpwhoisPackagist | <= 4.2.5 | — |
david-garcia/phpwhoisPackagist | <= 4.3.1 | — |
ivankristianto/phpwhoisPackagist | <= 4.3.0 | — |
kazist/phpwhoisPackagist | <= 4.2.6 | — |
serluck/phpwhoisPackagist | <= 4.2.6 | — |
simple-updates/phpwhoisPackagist | <= 1.0.0 | — |
truckersmp/phpwhoisPackagist | <= 4.3.1 | — |
Affected products
10- ghsa-coords9 versionspkg:composer/jsmitty12/phpwhoispkg:composer/phpwhois/phpwhoispkg:composer/brightlocal/phpwhoispkg:composer/david-garcia/phpwhoispkg:composer/ivankristianto/phpwhoispkg:composer/kazist/phpwhoispkg:composer/serluck/phpwhoispkg:composer/simple-updates/phpwhoispkg:composer/truckersmp/phpwhois
< 5.1.0+ 8 more
- (no CPE)range: < 5.1.0
- (no CPE)range: <= 4.2.5
- (no CPE)range: <= 4.2.5
- (no CPE)range: <= 4.3.1
- (no CPE)range: <= 4.3.0
- (no CPE)range: <= 4.2.6
- (no CPE)range: <= 4.2.6
- (no CPE)range: <= 1.0.0
- (no CPE)range: <= 4.3.1
Patches
Vulnerability mechanics
References
16- github.com/Gemorroj/phpwhois/commit/91c937e03c876ba1290b6de2a3ad953d2105fdd0nvdPatchThird Party AdvisoryWEB
- github.com/sparc/phpWhois.org/commit/5cc572490c9053d46598ec9348a11e36a5a33a46nvdPatchVendor AdvisoryWEB
- github.com/sbaresearch/advisories/tree/public/2018/SBA-ADV-20180425-01_phpWhois_Code_ExecutionnvdExploitThird Party AdvisoryWEB
- blog.nettitude.com/uk/cve-2015-5243-phpwhois-remote-code-executionnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-c95f-27gx-6vq9ghsaADVISORY
- github.com/jsmitty12/phpWhois/blob/master/CHANGELOG.mdnvdRelease NotesThird Party AdvisoryWEB
- github.com/jsmitty12/phpWhois/issues/19nvdIssue TrackingThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2015-5243ghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/brightlocal/phpwhois/CVE-2015-5243.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/david-garcia/phpwhois/CVE-2015-5243.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/ivankristianto/phpwhois/CVE-2015-5243.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/kazist/phpwhois/CVE-2015-5243.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/phpwhois/phpwhois/CVE-2015-5243.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/serluck/phpwhois/CVE-2015-5243.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/simple-updates/phpwhois/CVE-2015-5243.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/truckersmp/phpwhois/CVE-2015-5243.yamlghsaWEB
News mentions
0No linked articles in our index yet.