![]() |
Inicial ▼ Bookkeeping
Online ▼ Auditorias ▼
DNS
Administrado ▼
Acerca de DNS
Ordenar/Renovar
Preguntas Frecuentes
AUP
Dynamic DNS Clients
Configurar Dominios Dynamic DNS Update Password Monitoreo
de Redes ▼
Enterprise
Avanzado
Estándarr
Prueba
Preguntas Frecuentes
Resumen de Precio/Funciones
Ordenar
Muestras
Configure/Status Alert Profiles | ||
ID de Prueba: | 1.3.6.1.4.1.25623.1.0.100594 |
Categoría: | Web application abuses |
Título: | PHP Str_Replace() Integer Overflow Vulnerability |
Resumen: | PHP is prone to an integer-overflow vulnerability because it; fails to ensure that integer values aren't overrun. Attackers; may exploit this issue to cause a buffer-overflow and corrupt; process memory. |
Descripción: | Summary: PHP is prone to an integer-overflow vulnerability because it fails to ensure that integer values aren't overrun. Attackers may exploit this issue to cause a buffer-overflow and corrupt process memory. Vulnerability Impact: Exploiting this issue may allow attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely result in a denial-of-service condition. Affected Software/OS: This issue affects versions prior to PHP 4.4.5 and 5.2.1. Solution: The vendor released PHP 4.4.5 and 5.2.1 to address this issue. Please see the references for more information. CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2007-1885 BugTraq ID: 23233 http://www.securityfocus.com/bid/23233 HPdes Security Advisory: HPSBMA02215 http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01056506 HPdes Security Advisory: HPSBTU02232 http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01086137 HPdes Security Advisory: SSRT071423 HPdes Security Advisory: SSRT071429 http://www.php-security.org/MOPB/MOPB-39-2007.html http://secunia.com/advisories/25423 http://secunia.com/advisories/25850 http://www.vupen.com/english/advisories/2007/1991 http://www.vupen.com/english/advisories/2007/2374 XForce ISS Database: php-strreplace-bo(33767) https://exchange.xforce.ibmcloud.com/vulnerabilities/33767 Common Vulnerability Exposure (CVE) ID: CVE-2007-1886 XForce ISS Database: php-strreplace-single-unspecified(33768) https://exchange.xforce.ibmcloud.com/vulnerabilities/33768 |
Copyright | Copyright (C) 2010 Greenbone Networks GmbH |
Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |