PHP version 4.3.9 is vulnerable to meta character attacks. The bug could enable an attacker to read arbitrary files from the filesystem of a webserver that hosts PHP scripts.
In addition PHP versions 4.3.6 until 4.3.9 as well as PHP versions 5.0.0 until 5.0.2 contain a bug that enables an attacker to manipulate the file name of uploaded files to perform directory traversal.
While both vulnerabilities exist in windows and unix platform versions of PHP, they can only be successfully exploited on windows systems.
For more information on these vulnerabilities, see the SecurityFocus page.
You should update your version of PHP quickly!
PHP Vulnerabilities !
Posted on Thursday, December 16, 2004 @ 20:31:09 CST in Security
|
PHP-Nuke Patched 2.8
Posted on Tuesday, December 14, 2004 @ 10:23:12 CST in Security chatserv writes:
|
Changing admin.php name in 7.6
Posted on Wednesday, December 08, 2004 @ 08:18:11 CST in Security Mesum writes:
|
PHP-Nuke Patched 2.7
Posted on Wednesday, November 24, 2004 @ 18:47:00 CST in Security
|
PHP Security Breach! Update Immediately!
Posted on Friday, November 19, 2004 @ 18:28:49 CST in Security
|
Flux Spreads Wider
Posted on Sunday, November 07, 2004 @ 17:01:49 CST in Security sharlein writes:
|