Computer Security
[EN] securityvulns.ru
no-pyccku



Multiple PHP bugs
updated since 27.02.2002
Published:04.03.2007
Source:BUGTRAQ
SecurityVulns ID:1818
Type:local
Level:6/10
Description:Buffer overflows, integer overflows, DoS conditions, crossite scripting.
Affected:PHP : PHP 3.10
 PHP : PHP 4.0
 PHP : PHP 4.2
 PHP : PHP 4.3
 PHP : PHP 4.4
CVE:CVE-2007-1287 (A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP 6.0 in CVS, allows remote attackers to conduct cross-site scripting (XSS) attacks via GET, POST, or COOKIE array values, which are not escaped in the phpinfo output, as originally fixed for CVE-2005-3388.)
 CVE-2005-3388 (Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment.")
Original documentdocumentPHP-SECURITY, MOPB-08-2007:PHP 4 phpinfo() XSS Vulnerability (Deja-vu) (04.03.2007)
 documentsilent needel, PHP XSS exploit in phpinfo() (05.06.2003)
 documentSverre H. Huseby, PHP Trans SID XSS (Was: New php release with security fixes) (02.06.2003)
 documentPHP, PHP 4.3.2 released (30.05.2003)
 documentX-FORCE, ISS Brief: Remote Compromise and Denial of Service Vulnerability in PHP (23.07.2002)
 documentCERT, Advisory CA-2002-21 Vulnerability in PHP (23.07.2002)
 documentMatthew Murphy, PHP Resource Exhaustion Denial of Service (23.07.2002)
 documentPHP, Security Advisory: Vulnerability in PHP versions 4.2.0 and 4.2.1 (22.07.2002)
 documentsecurity_(at)_e-matters.de, Advisory 02/2002: PHP remote vulnerability (22.07.2002)
 documentsecurity_(at)_e-matters.de, Advisory 012002: PHP remote vulnerabilities (28.02.2002)
 documentCERT, Advisory CA-2002-05 Multiple Vulnerabilities in PHP fileupload (28.02.2002)
 documentX-FORCE, Multiple PHP Vulnerabilities - Remote Compromise Exploit in Circulation (27.02.2002)
Files:Apache PHP DoS
 PHP 4 - phpinfo() XSS Testcase
 Apache+php Proof of Concept Exploit
 x86/linux mod_php v4.0.2rc1-v4.0.5 remote exploit
Discuss:Read or add your comments to this news (0 comments)


Show Threads
Messages
 
Login:* (Register)
Password:*
(private) To:
(reply) Subject:*
Text:

Main Forum (Eng)

General security questions not appropriate for another forums.
3proxy Forum (Eng)

All 3proxy question must be posted to this forum.
Bugs, Vulnerabilities, PoCs and Exploits (Eng)

All vulnerability related questions, vulnerability digging and exploit creation.
Windows programming and administration (Eng)

Administering Windows and application development.
Unix programming and administation (Eng)

Administering Unix and application development.
Test forum

Please post all test messages here. All test messages from different forums will be deteted.
Main Forum (Rus)
3proxy Forum (Rus)
Bugs, Vulnerabilities, PoCs and Exploits (Rus)
Windows programming and administration (Rus)
Unix programming and administation (Rus)
About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru