Computer Security
[EN] securityvulns.ru no-pyccku


PHP CDFP extension cpdf_open information leak
Published:10.03.2007
Source:
SecurityVulns ID:7378
Type:library
Threat Level:
5/10
Description:Fragment of source code is printed in diagnostics message.
Affected:PHP : PHP 4.4
CVE:CVE-2007-1452 (The FDF support (ext/fdf) in PHP 5.2.0 and earlier does not implement the input filtering hooks for ext/filter, which allows remote attackers to bypass web site filters via an application/vnd.fdf formatted POST.)
 CVE-2007-1412 (The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensitive information (script source code) via a long string in the second argument.)
Files:PHP 4.4.6 cpdf_open() source code disclosure poc

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod