[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2465-1 php5 -- several

ID: oval:org.secpod.oval:def:600798Date: (C)2012-05-14   (M)2023-02-20
Class: PATCHFamily: unix




De Eindbazen discovered that PHP, when run with mod_cgi, will interpret a query string as command line parameters, allowing to execute arbitrary code. Additionally, this update fixes insufficient validation of upload name which lead to corrupted $_FILES indices.

Platform:
Debian 6.0
Product:
php5
Reference:
DSA-2465-1
CVE-2012-1172
CVE-2012-1823
CVE-2012-2311
CVE    3
CVE-2012-1172
CVE-2012-2311
CVE-2012-1823
CPE    119
cpe:/a:php:php:3.0
cpe:/a:php:php:5.0.0:rc3
cpe:/a:php:php:5.0.0:rc2
cpe:/a:php:php:5.0.0:rc1
...

© SecPod Technologies