exploits , vulnerabilities , articles , PHP 5.2.4 and Prior Versions Multiple Vulnerabilities
| Title |
PHP 5.2.4 and Prior Versions Multiple Vulnerabilities |
| Published |
2007-11-08-12:00AM |
| Updated |
2008-03-19-02:40PM |
| Class |
Unknown |
| CVE |
CVE-2007-4887 E-2007-4783CV 2007-4840CVE- 07-5898CVE-20 -5899CVE-2007 900CVE-2007-4 2CVE-2007-478 |
| Remote |
Yes |
| Local |
Yes |
| Credit |
Laurent Gaffie, Rasmus Lerdorf and SecurityReason are credited with the discovery of these vulnerabilities. |
| Vulnerable |
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux 12.0 Slackware Linux 11.0 Slackware Linux current S.u.S.E. SLE SDK 9 S.u.S.E. SLE SDK 10.SP1 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. OpenEnterpriseServer 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9 S.u.S.E. Linux 10.1 x8664 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc rPath rPath Linux 1 PHP PHP 5.2.4 PHP PHP 5.2.3 PHP PHP 5.2.2 PHP PHP 5.2.1 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 PHP PHP 5.1.6 PHP PHP 5.1.5 PHP PHP 5.1.4 PHP PHP 5.1.3 PHP PHP 5.1.3 PHP PHP 5.1.2 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 PHP PHP 5.1.1 PHP PHP 5.1 PHP PHP 5.0.5 PHP PHP 5.0.4 PHP PHP 5.0.3 Trustix Secure Linux 2.2 PHP PHP 5.0.2 PHP PHP 5.0.1 PHP PHP 5.0 candidate 3 PHP PHP 5.0 candidate 2 PHP PHP 5.0 candidate 1 PHP PHP 5.0 .0 PHP PHP 4.4.7 Slackware Linux 10.2 Slackware Linux 11.0 Slackware Linux current PHP PHP 4.4.6 PHP PHP 4.4.5 PHP PHP 4.4.4 PHP PHP 4.4.3 PHP PHP 4.4.2 PHP PHP 4.4.1 PHP PHP 4.4 .0 PHP PHP 4.3.11 PHP PHP 4.3.10 Gentoo Linux RedHat Fedora Core3 Trustix Secure Enterprise Linux 2.0 Trustix Secure Linux 2.2 Trustix Secure Linux 2.1 Trustix Secure Linux 2.0 Trustix Secure Linux 1.5 PHP PHP 4.3.9 PHP PHP 4.3.8 PHP PHP 4.3.7 PHP PHP 4.3.6 PHP PHP 4.3.5 PHP PHP 4.3.4 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Linux Mandrake 10.0 AMD64 MandrakeSoft Linux Mandrake 10.0 S.u.S.E. Linux Personal 9.1 PHP PHP 4.3.3 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 Turbolinux Home Turbolinux Turbolinux 10 F... Turbolinux Turbolinux Desktop 10.0 PHP PHP 4.3.2 PHP PHP 4.3.1 MandrakeSoft Linux Mandrake 9.1 ppc MandrakeSoft Linux Mandrake 9.1 OpenPKG OpenPKG Current S.u.S.E. Linux Personal 8.2 PHP PHP 4.3 PHP PHP 4.2.3 EnGarde Secure Linux 1.0.1 MandrakeSoft Corporate Server 2.1 x86_64 MandrakeSoft Corporate Server 2.1 MandrakeSoft Linux Mandrake 9.0 Turbolinux Turbolinux Server 8.0 Turbolinux Turbolinux Server 7.0 Turbolinux Turbolinux Workstation 8.0 Turbolinux Turbolinux Workstation 7.0 PHP PHP 4.2.2 Gentoo Linux 1.4 _rc1 Gentoo Linux 1.2 OpenPKG OpenPKG 1.1 RedHat Linux 8.0 i386 RedHat Linux 8.0 S.u.S.E. Linux 8.1 PHP PHP 4.2.1 FreeBSD FreeBSD 4.6 FreeBSD FreeBSD 4.5 FreeBSD FreeBSD 4.4 FreeBSD FreeBSD 4.3 Slackware Linux 8.1 PHP PHP 4.2 .0 PHP PHP 4.2 dev PHP PHP 4.1.2 Apple Mac OS X 10.1.5 Apple Mac OS X 10.1.4 Apple Mac OS X 10.1.3 Apple Mac OS X 10.1.2 Apple Mac OS X 10.1.1 Apple Mac OS X 10.1 Apple Mac OS X 10.1 Apple Mac OS X 10.0.4 Apple Mac OS X 10.0.3 Apple Mac OS X 10.0.2 Apple Mac OS X 10.0.1 Apple Mac OS X 10.0 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia64 Debian Linux 3.0 ia32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha MandrakeSoft Linux Mandrake 8.2 ppc MandrakeSoft Linux Mandrake 8.2 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Single Network Firewall 7.2 PHP PHP 4.1.1 Conectiva Linux 7.0 PHP PHP 4.1 .0 S.u.S.E. Linux 8.0 i386 S.u.S.E. Linux 8.0 PHP PHP 4.0.7 RC3 PHP PHP 4.0.7 RC2 PHP PHP 4.0.7 RC1 PHP PHP 4.0.7 PHP PHP 4.0.6 Caldera OpenLinux Server 3.1.1 Caldera OpenLinux Server 3.1 Caldera OpenLinux Workstation 3.1.1 Caldera OpenLinux Workstation 3.1 HP Secure OS software for Linux 1.0 IBM AIX 4.3.3 IBM AIX 4.3.2 IBM AIX 4.3.1 IBM AIX 4.3 IBM AIX 5.1 MandrakeSoft Corporate Server 1.0.1 MandrakeSoft Linux Mandrake 8.1 ia64 MandrakeSoft Linux Mandrake 8.1 MandrakeSoft Linux Mandrake 8.0 ppc MandrakeSoft Linux Mandrake 8.0 MandrakeSoft Linux Mandrake 7.2 MandrakeSoft Linux Mandrake 7.1 RedHat Linux 7.2 ia64 RedHat Linux 7.2 i386 RedHat Linux 7.2 RedHat Linux 7.1 ia64 RedHat Linux 7.1 i386 RedHat Linux 7.1 alpha RedHat Linux 7.1 RedHat Linux 7.0 i386 RedHat Linux 7.0 alpha RedHat Linux 7.0 S.u.S.E. Linux 7.3 sparc S.u.S.E. Linux 7.3 ppc S.u.S.E. Linux 7.3 i386 S.u.S.E. Linux 7.3 S.u.S.E. Linux 7.2 i386 S.u.S.E. Linux 7.2 Sun Cobalt RaQ 550 Sun LX50 Trustix Secure Linux 1.5 PHP PHP 4.0.5 PHP PHP 4.0.3 pl1 S.u.S.E. Linux 6.4 ppc S.u.S.E. Linux 6.4 i386 S.u.S.E. Linux 6.4 alpha S.u.S.E. Linux 6.4 PHP PHP 4.0.3 Debian Linux 2.2 sparc Debian Linux 2.2 powerpc Debian Linux 2.2 IA32 Debian Linux 2.2 arm Debian Linux 2.2 alpha Debian Linux 2.2 68k Debian Linux 2.2 Sun Cobalt Control Station 4100CS Sun Cobalt Qube3 Japanese 4000WGJ Sun Cobalt Qube3 Japanese w/ Caching and RAID 4100WGJ Sun Cobalt Qube3 Japanese w/Caching 4010WGJ Sun Cobalt RaQ XTR 3500R Sun Cobalt RaQ XTR Japanese 3500Rja PHP PHP 4.0.2 PHP PHP 4.0.1 pl2 PHP PHP 4.0.1 pl1 PHP PHP 4.0.1 Sun Cobalt Qube3 4000WG Sun Cobalt Qube3 w/ Caching and RAID 4100WG Sun Cobalt Qube3 w/Caching 4010WG Sun Cobalt RaQ4 3001R Sun Cobalt RaQ4 Japanese RAID 3100Rja Sun Cobalt RaQ4 RAID 3100R PHP PHP 5.2 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia64 Debian Linux 4.0 ia32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 HP HPUX B.11.31 HP HPUX B.11.23 HP HPUX B.11.11 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia64 Debian Linux 4.0 ia32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Apple Mac OS X Server 10.5.2 Apple Mac OS X 10.5.2
|
| Not Vulnerable |
PHP PHP 5.2.5
|
| Code |
Exploiting some of these issues depends on the configuration of the application employing the vulnerable PHP version. To exploit some of these issues, an attacker must have local access; for other issues, the attacker can use a browser.The following proofs of concept are available:php -r'dl(str_repeat("0",27999991));' /data/vulnerabilities/exploits/26403.php |
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Sat, 22 Nov 2008 22:07:12 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.bestop www.trisha Sakilasex. CMS is Fre Windows Re punjabsex. mambo Remo Mana news for c punjabsex. mambo Remo mambo Remo /kboard//k PHP guestb Www.sexyma penny.smit mambo Remo man and wo mambo Remo WWW.18 yea crew www.oldmo. +Www.Sexy+ NuContent BRIGHT download. ncftp porn badjoj Burning WWW.18+yea badjoj php-nuke 2 news for C RAP WWW.TOLLYW Sakilasex. xxxmouve www.blacks J-a-p-a-n freedownlo nucked t723t download. download. 200 /compo news for C CMS is Fre Free video phpbb/send
|