SecurityLex.Org
  Home My IP SecCon Glossary Vulnerability Tests Sans/FBI Top 20 Top 10 Ipfilter Recent Vulnerabilities Today's news Web Host Check 

VulnTests
SecureScout Testcase
eEye Retina RTH
Nessus Plugin ID
nCircle Sans CVE's
Dragonsoft Vuln ID
CVE Entries
Search CVSS vectors 
CVSS Base score between    and
Access Vector Confidentiality Impact
Access Complexity Integrity Impact
Authentification Availability Impact
Impact Bias

Your search for "2829" returned:
Dragonsoft Vuln ID: 2829Name: PHP HTMLEntities HTMLSpecialChars Buffer Overflow Vulnerabilities
CVE References: CVE-2006-5465 (cve.mitre.org, nvd.nist.gov
SANS/FBI TOP20 Reference:
Group/Family: Web Servers
Risk: High
TC Impact: n/aService: n/aVuln Impact: Gain System Privileges
Access Vector: RemoteAccess Complexity: Authentication:
Description: PHP before versions 5.2.0 is exist buffer overflow vulnerability in htmlentities() and htmlspecialchars() HTML entity encoder functions. A remote attacker could execute arbitrary code on the system by send specially-crafted UTF-8 characters to the function.

Affect OS: Windows, UNIX
Remediation: Refer The PHP Group Web site - "PHP: Downloads link, Upgrade to PHP 5.2.0 or higher version.
Created: 2007-03-07 19:27:32Last Changed: 2007-04-27 15:26:56
 
 The Complete Lexicon to Security