PDA

Click to See Complete Forum and Search --> : Multiple Vulnerabilities in PHP fileupload


zigar
March 5th, 2002, 08:19 PM
Hi y'all...back from a couple days away....

full info at:

http://www.cert.org/advisories/CA-2002-05.html


Systems Affected
Web servers running PHP
Overview
Multiple vulnerabilities exist in the PHP scripting language. These vulnerabilities could allow a remote attacker to execute arbitrary code with the privileges of the PHP process.

I. Description
PHP is a scripting language widely used in web development. PHP can be installed on a variety of web servers, including Apache, IIS, Caudium, Netscape and iPlanet, OmniHTTPd and others. Vulnerabilities in the php_mime_split function may allow an intruder to execute arbitrary code with the privileges of the web server. For additional details, see

http://security.e-matters.de/advisories/012002.html

gstudios
March 5th, 2002, 08:27 PM
It seems as though, we both thought it was important. :D

http://www.antionline.com/showthread.php?threadid=220635

Noia
March 5th, 2002, 08:35 PM
PHP Problems are widespread, and not really new info, but very informativ.....
Nice post....

- Noia

zigar
March 6th, 2002, 01:19 AM
and not really new info

actually these ARE new exploits..(since last wednesday anyways....and they are just a wee bit scary..... :eek:

Story Link (www.newsnow.co.uk/cgi/NGoto/11784402?-2622)



"...Netcraft released its monthly survey of Web sites, indicating that nearly 8.4 million sites were hosted by servers that use a vulnerable version of PHP. One million of those sites are vulnerable to attack, the survey said.

Based on that data alone, the PHP flaws could be as dangerous as the indexing server ISAPI filter flaw in Microsoft's Internet Information Server that made the Code Red worm possible, said Marc Maiffret, chief hacking officer for network protection company eEye Digital Security"