Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.100605
Categoría:Web application abuses
Título:PHP < 4.4.5, 5.x < 5.2.1 RCE Vulnerability
Resumen:PHP is prone to a remote code execution (RCE); vulnerability.
Descripción:Summary:
PHP is prone to a remote code execution (RCE)
vulnerability.

Vulnerability Insight:
The shmop functions in PHP do not verify that their arguments
correspond to a shmop resource, which allows context-dependent attackers to read and write
arbitrary memory locations via arguments associated with an inappropriate resource, as
demonstrated by a GD Image resource.

Vulnerability Impact:
An attacker may exploit this issue to execute arbitrary code
within the context of the affected webserver. The attacker may also gain access to RSA keys of the
SSL certificate.

Affected Software/OS:
PHP prior to version 4.4.5 and 5.x prior to 5.2.1.

Solution:
Update to version 4.4.5, 5.2.1 or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2007-1376
BugTraq ID: 22862
http://www.securityfocus.com/bid/22862
Debian Security Information: DSA-1283 (Google Search)
http://www.debian.org/security/2007/dsa-1283
https://www.exploit-db.com/exploits/3426
https://www.exploit-db.com/exploits/3427
http://security.gentoo.org/glsa/glsa-200703-21.xml
http://www.php-security.org/MOPB/MOPB-15-2007.html
http://www.osvdb.org/32781
http://secunia.com/advisories/24606
http://secunia.com/advisories/25056
http://secunia.com/advisories/25057
http://secunia.com/advisories/25062
SuSE Security Announcement: SUSE-SA:2007:032 (Google Search)
http://www.novell.com/linux/security/advisories/2007_32_php.html
http://www.ubuntu.com/usn/usn-455-1
CopyrightCopyright (C) 2010 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.