Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.803337
Categoría:Web application abuses
Título:PHP Multiple Vulnerabilities (Mar 2013) - Windows
Resumen:PHP is prone to multiple vulnerabilities.
Descripción:Summary:
PHP is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to:

- Does not validate 'soap.wsdl_cache_dir' directive before writing SOAP wsdl
cache files to the filesystem.

- Allows the use of external entities while parsing SOAP wsdl files, issue
in 'soap_xmlParseFile' and 'soap_xmlParseMemory' functions.

Vulnerability Impact:
Successful exploitation allows attackers to read arbitrary files and write
wsdl files within the context of the affected application.

Affected Software/OS:
PHP version before 5.3.23 and 5.4.x before 5.4.13

Solution:
Update to PHP 5.4.13 or 5.3.23, which will be available soon.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2013-1635
http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html
Debian Security Information: DSA-2639 (Google Search)
http://www.debian.org/security/2013/dsa-2639
http://www.mandriva.com/security/advisories?name=MDVSA-2013:114
SuSE Security Announcement: SUSE-SU-2013:1285 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00034.html
SuSE Security Announcement: SUSE-SU-2013:1315 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00006.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-1643
RedHat Security Advisories: RHSA-2013:1307
http://rhn.redhat.com/errata/RHSA-2013-1307.html
RedHat Security Advisories: RHSA-2013:1615
http://rhn.redhat.com/errata/RHSA-2013-1615.html
http://secunia.com/advisories/55078
http://www.ubuntu.com/usn/USN-1761-1
CopyrightCopyright (C) 2013 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.