Lucene search

K
nessusTenable4493.PRM
HistoryMay 02, 2008 - 12:00 a.m.

PHP 5.x < 5.2.6 Multiple Vulnerabilities

2008-05-0200:00:00
Tenable
www.tenable.com
156

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.245

Percentile

96.7%

According to its banner, the version of PHP 5.x installed on the remote host is older than 5.2.6. Such versions may be affected by the following issues :

  • A stack buffer overflow in FastCGI SAPI.
  • An integer overflow in printf().
  • An unspecified security issue tracked by CVE-2008-0599.
  • A safe_mode bypass in cURL.
  • Incomplete handling of multibyte chars inside escapeshellcmd().
  • Issues in the bundled PCRE fixed by version 7.6.
Binary data 4493.prm

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.245

Percentile

96.7%