Description
The Zend Engine in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information by interrupting the handler for the (1) ZEND_BW_XOR opcode (shift_left_function), (2) ZEND_SL opcode (bitwise_xor_function), or (3) ZEND_SR opcode (shift_right_function), related to the convert_to_long_base function.
Remediation
References
Related Vulnerabilities
WordPress Plugin Database Backup for WordPress Cross-Site Scripting (2.3.3)
WordPress Plugin Read Offline Cross-Site Scripting (0.9.17)
WordPress Plugin Password Vault Cross-Site Scripting (1.8.2)
ownCloud Exposure of Resource to Wrong Sphere Vulnerability (CVE-2020-36252)
SugarCRM Missing Authorization Vulnerability (CVE-2020-7472)