Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.100594
Categoría:Web application abuses
Título:PHP Str_Replace() Integer Overflow Vulnerability
Resumen:PHP is prone to an integer-overflow vulnerability because it; fails to ensure that integer values aren't overrun. Attackers; may exploit this issue to cause a buffer-overflow and corrupt; process memory.
Descripción:Summary:
PHP is prone to an integer-overflow vulnerability because it
fails to ensure that integer values aren't overrun. Attackers
may exploit this issue to cause a buffer-overflow and corrupt
process memory.

Vulnerability Impact:
Exploiting this issue may allow attackers to execute arbitrary machine
code in the context of the affected application. Failed exploit
attempts will likely result in a denial-of-service condition.

Affected Software/OS:
This issue affects versions prior to PHP 4.4.5 and 5.2.1.

Solution:
The vendor released PHP 4.4.5 and 5.2.1 to address this issue. Please
see the references for more information.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2007-1885
BugTraq ID: 23233
http://www.securityfocus.com/bid/23233
HPdes Security Advisory: HPSBMA02215
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01056506
HPdes Security Advisory: HPSBTU02232
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01086137
HPdes Security Advisory: SSRT071423
HPdes Security Advisory: SSRT071429
http://www.php-security.org/MOPB/MOPB-39-2007.html
http://secunia.com/advisories/25423
http://secunia.com/advisories/25850
http://www.vupen.com/english/advisories/2007/1991
http://www.vupen.com/english/advisories/2007/2374
XForce ISS Database: php-strreplace-bo(33767)
https://exchange.xforce.ibmcloud.com/vulnerabilities/33767
Common Vulnerability Exposure (CVE) ID: CVE-2007-1886
XForce ISS Database: php-strreplace-single-unspecified(33768)
https://exchange.xforce.ibmcloud.com/vulnerabilities/33768
CopyrightCopyright (C) 2010 Greenbone Networks GmbH

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.