Lucene search

K
jvnJapan Vulnerability NotesJVN:64459670
HistoryMay 20, 2015 - 12:00 a.m.

JVN#64459670: mt-phpincgi vulnerable to PHP object injection

2015-05-2000:00:00
Japan Vulnerability Notes
jvn.jp
15

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.01 Low

EPSS

Percentile

83.5%

mt-phpincgi is script that runs Movable Type templates as PHP. mt-phpincgi contains a PHP object Injection vulnerability.

According to the reporter, attacks that attempt to exploit this vulnerability have been confirmed.

Impact

Arbitrary PHP code may be executed on the server by an unauthenticated attacker.

Solution

Apply the update
The developer has released an update at mt-phpincgi.php security update.
Apply the update according to the information provided by the developer.

Products Affected

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.01 Low

EPSS

Percentile

83.5%

Related for JVN:64459670