Lucene search

K
gentooGentoo FoundationGLSA-200507-07
HistoryJul 10, 2005 - 12:00 a.m.

phpWebSite: Multiple vulnerabilities

2005-07-1000:00:00
Gentoo Foundation
security.gentoo.org
19

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.956 High

EPSS

Percentile

99.4%

Background

phpWebSite is a content management system written in PHP.

Description

phpWebSite fails to sanitize input sent to the XML-RPC server using the “POST” method. Other unspecified vulnerabilities have been discovered by Diabolic Crab of Hackers Center.

Impact

A remote attacker could exploit the XML-RPC vulnerability to execute arbitrary PHP script code by sending specially crafted XML data to phpWebSite. The undisclosed vulnerabilities do have an unknown impact.

Workaround

There is no known workaround at this time.

Resolution

All phpWebSite users should upgrade to the latest available version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=www-app/phpwebsite-0.10.1-r1"
OSVersionArchitecturePackageVersionFilename
Gentooanyallwww-apps/phpwebsite< 0.10.1-r1UNKNOWN

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.956 High

EPSS

Percentile

99.4%