exploits , vulnerabilities , articles , PHP PHPInfo Cross-Site Scripting Vulnerability
| Title |
PHP PHPInfo Cross-Site Scripting Vulnerability |
| Published |
2002-10-12-12:00AM |
| Updated |
2005-10-31-09:04PM |
| Class |
Input Validation Error |
| CVE |
CVE-MAP-NOMATCH |
| Remote |
Yes |
| Local |
No |
| Credit |
Matthew Murphy is credited with the initial discovery of this vulnerability. |
| Vulnerable |
PHP PHP 4.4 .0
PHP PHP 4.3.11
PHP PHP 4.3.10
Gentoo Linux
RedHat Fedora Core3
Trustix Secure Enterprise Linux 2.0
Trustix Secure Linux 1.5
Trustix Secure Linux 2.0
Trustix Secure Linux 2.1
Trustix Secure Linux 2.2
PHP PHP 4.3.9
PHP PHP 4.3.8
MandrakeSoft Linux Mandrake 10.1
MandrakeSoft Linux Mandrake 10.1 x86_64
S.u.S.E. Linux Personal 9.2
Turbolinux Turbolinux Server 10.0
Ubuntu Ubuntu Linux 4.1 ia32
Ubuntu Ubuntu Linux 4.1 ia64
Ubuntu Ubuntu Linux 4.1 ppc
PHP PHP 4.3.7
PHP PHP 4.3.6
PHP PHP 4.3.5
PHP PHP 4.3.4
MandrakeSoft Corporate Server 3.0
MandrakeSoft Corporate Server 3.0 x86_64
MandrakeSoft Linux Mandrake 10.0
MandrakeSoft Linux Mandrake 10.0 amd64
S.u.S.E. Linux Personal 9.1
PHP PHP 4.3.3
S.u.S.E. Linux Personal 9.0
S.u.S.E. Linux Personal 9.0 x86_64
Turbolinux Home
Turbolinux Turbolinux 10 F...
Turbolinux Turbolinux Desktop 10.0
PHP PHP 4.3.2
PHP PHP 4.3.1
MandrakeSoft Linux Mandrake 9.1
MandrakeSoft Linux Mandrake 9.1 ppc
OpenPKG OpenPKG Current
S.u.S.E. Linux Personal 8.2
PHP PHP 4.3
PHP PHP 4.2.3
EnGarde Secure Linux 1.0.1
MandrakeSoft Corporate Server 2.1
MandrakeSoft Corporate Server 2.1 x86_64
MandrakeSoft Linux Mandrake 9.0
Turbolinux Turbolinux Server 7.0
Turbolinux Turbolinux Server 8.0
Turbolinux Turbolinux Workstation 7.0
Turbolinux Turbolinux Workstation 8.0
PHP PHP 4.2.2
Gentoo Linux 1.2
Gentoo Linux 1.4 _rc1
OpenPKG OpenPKG 1.1
RedHat Linux 8.0
RedHat Linux 8.0 i386
S.u.S.E. Linux 8.1
PHP PHP 4.2.1
FreeBSD FreeBSD 4.3
FreeBSD FreeBSD 4.4
FreeBSD FreeBSD 4.5
FreeBSD FreeBSD 4.6
Slackware Linux 8.1
PHP PHP 4.2 .0
PHP PHP 4.2 dev
PHP PHP 4.1.2
Apple Mac OS X 10.0
Apple Mac OS X 10.0.1
Apple Mac OS X 10.0.2
Apple Mac OS X 10.0.3
Apple Mac OS X 10.0.4
Apple Mac OS X 10.1
Apple Mac OS X 10.1
Apple Mac OS X 10.1.1
Apple Mac OS X 10.1.2
Apple Mac OS X 10.1.3
Apple Mac OS X 10.1.4
Apple Mac OS X 10.1.5
Debian Linux 3.0 alpha
Debian Linux 3.0 arm
Debian Linux 3.0 hppa
Debian Linux 3.0 ia32
Debian Linux 3.0 ia64
Debian Linux 3.0 m68k
Debian Linux 3.0 mips
Debian Linux 3.0 mipsel
Debian Linux 3.0 ppc
Debian Linux 3.0 s/390
Debian Linux 3.0 sparc
MandrakeSoft Linux Mandrake 8.2
MandrakeSoft Linux Mandrake 8.2 ppc
MandrakeSoft Multi Network Firewall 2.0
MandrakeSoft Single Network Firewall 7.2
PHP PHP 4.1.1
Conectiva Linux 7.0
PHP PHP 4.1 .0
S.u.S.E. Linux 8.0
S.u.S.E. Linux 8.0 i386
PHP PHP 4.0.7 RC3
PHP PHP 4.0.7 RC2
PHP PHP 4.0.7 RC1
PHP PHP 4.0.7
PHP PHP 4.0.6
Caldera OpenLinux Server 3.1
Caldera OpenLinux Server 3.1.1
Caldera OpenLinux Workstation 3.1
Caldera OpenLinux Workstation 3.1.1
HP Secure OS software for Linux 1.0
IBM AIX 4.3
IBM AIX 4.3.1
IBM AIX 4.3.2
IBM AIX 4.3.3
IBM AIX 5.1
MandrakeSoft Corporate Server 1.0.1
MandrakeSoft Linux Mandrake 7.1
MandrakeSoft Linux Mandrake 7.2
MandrakeSoft Linux Mandrake 8.0
MandrakeSoft Linux Mandrake 8.0 ppc
MandrakeSoft Linux Mandrake 8.1
MandrakeSoft Linux Mandrake 8.1 ia64
RedHat Linux 7.0
RedHat Linux 7.0 alpha
RedHat Linux 7.0 i386
RedHat Linux 7.1
RedHat Linux 7.1 alpha
RedHat Linux 7.1 i386
RedHat Linux 7.1 ia64
RedHat Linux 7.2
RedHat Linux 7.2 i386
RedHat Linux 7.2 ia64
S.u.S.E. Linux 7.2
S.u.S.E. Linux 7.2 i386
S.u.S.E. Linux 7.3
S.u.S.E. Linux 7.3 i386
S.u.S.E. Linux 7.3 ppc
S.u.S.E. Linux 7.3 sparc
Sun Cobalt RaQ 550
Sun LX50
Trustix Secure Linux 1.5
PHP PHP 4.0.5
PHP PHP 4.0.4
Compaq Compaq Secure Web Server PHP 1.0
Conectiva Linux 6.0
Guardian Digital Engarde Secure Linux 1.0.1
S.u.S.E. Linux 7.0
S.u.S.E. Linux 7.0 alpha
S.u.S.E. Linux 7.0 i386
S.u.S.E. Linux 7.0 ppc
S.u.S.E. Linux 7.0 sparc
S.u.S.E. Linux 7.1
S.u.S.E. Linux 7.1 alpha
S.u.S.E. Linux 7.1 ppc
S.u.S.E. Linux 7.1 sparc
S.u.S.E. Linux 7.1 x86
S.u.S.E. Linux 7.2
PHP PHP 4.0.3 pl1
S.u.S.E. Linux 6.4
S.u.S.E. Linux 6.4 alpha
S.u.S.E. Linux 6.4 i386
S.u.S.E. Linux 6.4 ppc
PHP PHP 4.0.3
Debian Linux 2.2
Debian Linux 2.2 68k
Debian Linux 2.2 alpha
Debian Linux 2.2 arm
Debian Linux 2.2 IA32
Debian Linux 2.2 powerpc
Debian Linux 2.2 sparc
Sun Cobalt Control Station 4100CS
Sun Cobalt Qube3 Japanese 4000WGJ
Sun Cobalt Qube3 Japanese w/ Caching and RAID 4100WGJ
Sun Cobalt Qube3 Japanese w/Caching 4010WGJ
Sun Cobalt RaQ XTR 3500R
Sun Cobalt RaQ XTR Japanese 3500Rja
PHP PHP 4.0.2
PHP PHP 4.0.1 pl2
PHP PHP 4.0.1 pl1
PHP PHP 4.0.1
Sun Cobalt Qube3 4000WG
Sun Cobalt Qube3 w/ Caching and RAID 4100WG
Sun Cobalt Qube3 w/Caching 4010WG
Sun Cobalt RaQ4 3001R
Sun Cobalt RaQ4 Japanese RAID 3100Rja
Sun Cobalt RaQ4 RAID 3100R
PHP PHP 4.0 0 |
| Not Vulnerable |
PHP PHP 4.4.1 |
| Code |
The following example was submitted:
http://www.example.com/info.php?variable=[code]
where [code] equals hostile HTML or script code.
|
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Thu, 17 Dec 2009 16:46:03 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Backup Exe niuma Crack Data STORY Phone chat Xxxsexmove zidonghua1 Www sexmov Xxxsexmove Running se Crack+Data Free Sex v news for c msn+8 Julee hscan none xx.gril li Bollywoods michael v www.julong www.dldvb. Shakee sex www.bastya http:/Trav www.dvex.c Cewe proxy_chec www.wanso. we live to WWW.YOU TO www.bollwo phpbb+file www.tamil Shakee sex Kamsutrase mambo Remo www.xvedio 200 //revi www.zhenxi www.bayued mambo Remo PHP Advanc PHP Advanc Www.sex v news for c NextGFX www.zhenxi www.xfailv saniya hot
|