Lucene search

K
nessusTenable6995.PRM
HistoryAug 20, 2013 - 12:00 a.m.

PHP < 5.3.11 Multiple Vulnerabilities

2013-08-2000:00:00
Tenable
www.tenable.com
18

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.025

Percentile

90.2%

PHP versions earlier than 5.3.11 are affected by the following vulnerabilities :

  • During the import of environment variables, temporary changes to the ‘magic_quotes_gpc’ directive are not handled properly. This can lower the difficulty for SQL injection attacks. (CVE-2012-0831)

  • The ‘$_FILES’ variable can be corrupted because the names of uploaded files are not properly validated. (CVE-2012-1172)

  • The ‘open_basedir’ directive is not properly handled by the functions ‘readline_write_history’ and ‘readline_read_history’.

  • The ‘header()’ function does not detect multi-line headers with a CR. (Bug #60227 / CVE-2011-1398)

Binary data 6995.prm
VendorProductVersionCPE
phpphpcpe:/a:php:php

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.025

Percentile

90.2%