PHP < 5.2.3 Multiple Vulnerabilities
|
|
Article ID: 25368
Last updated: 27 Jan, 2009
|
|
|
|
Views: 598
|
|
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.
|
|
PHP < 5.2.3 Multiple Vulnerabilities |
|
| This script is Copyright (C) 2007-2008 Tenable Network Security, Inc. |
|
|
| Family | CGI abuses |
| Plugin ID | 25368 |
| Bugtraq ID | 23359 24089 24259 24261
|
| CVE ID | CVE-2007-1900 CVE-2007-2756 CVE-2007-2872 CVE-2007-3007
|
|
| Description: |
Synopsis :
The remote web server uses a version of PHP that is affected by
multiple flaws.
Description :
According to its banner, the version of PHP installed on the remote
host is older than 5.2.3. Such versions may be affected by several
issues, including an integer overflow, safe_mode and open_basedir
bypass, and a denial of service vulnerability.
See also :
http://www.php.net/releases/5_2_3.php
Solution :
Upgrade to PHP version 5.2.3 or later.
Risk factor :
Medium / CVSS Base Score : 6.8
(CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P) |
|