Search:     Advanced search
server monitoring

PHP < 5.2.3 Multiple Vulnerabilities

Article ID: 25368
Last updated: 27 Jan, 2009
Views: 598
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

PHP < 5.2.3 Multiple Vulnerabilities

This script is Copyright (C) 2007-2008 Tenable Network Security, Inc.

FamilyCGI abuses
Plugin ID25368
Bugtraq ID23359
24089
24259
24261
CVE IDCVE-2007-1900
CVE-2007-2756
CVE-2007-2872
CVE-2007-3007

Description:

Synopsis :

The remote web server uses a version of PHP that is affected by
multiple flaws.

Description :

According to its banner, the version of PHP installed on the remote
host is older than 5.2.3. Such versions may be affected by several
issues, including an integer overflow, safe_mode and open_basedir
bypass, and a denial of service vulnerability.

See also :

http://www.php.net/releases/5_2_3.php

Solution :

Upgrade to PHP version 5.2.3 or later.

Risk factor :

Medium / CVSS Base Score : 6.8
(CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
This article was:   Helpful | Not Helpful
Prev   Next
Drupal Comment Function Arbitrary Code Execution     myServer 0.4.3 / 0.7 Directory Traversal Vulnerability