Lucene search

K
kasperskyKaspersky LabKLA10289
HistoryJul 06, 2014 - 12:00 a.m.

KLA10289 OSI vulnerability in PHP

2014-07-0600:00:00
Kaspersky Lab
threats.kaspersky.com
34

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

6.3 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

81.1%

An unspecified vulnerability was found in PHP. By exploiting this vulnerability malicious users can obtain sensitive information. This vulnerability can be exploited remotely at a point related to phpinfo.

Original advisories

Related products

PHP

CVE list

CVE-2014-4721 warning

Solution

Update to latest version

Impacts

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

Affected Products

  • PHP versions 5.4.29 and earlierPHP 5.5 versions 5.5.13 and earlier

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

6.3 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

81.1%