SecurityLex.Org
  Home My IP SecCon Glossary Vulnerability Tests Sans/FBI Top 20 Top 10 Ipfilter Recent Vulnerabilities Today's news Web Host Check 

VulnTests
SecureScout Testcase
eEye Retina RTH
Nessus Plugin ID
nCircle Sans CVE's
Dragonsoft Vuln ID
CVE Entries
Search CVSS vectors 
CVSS Base score between    and
Access Vector Confidentiality Impact
Access Complexity Integrity Impact
Authentification Availability Impact
Impact Bias

Your search for "31649" returned:
Nessus Plugin ID: 31649Name: PHP < 5.2 Multiple Vulnerabilities
CVE References: CVE-2006-5465 (cve.mitre.org, nvd.nist.gov
SANS/FBI TOP20 Reference:
Group/Family: CGI abuses
Risk: High
Description: Synopsis :

The remote web server uses a version of PHP that is affected by
multiple buffer overflows.

Description :

According to its banner, the version of PHP installed on the remote
host is older than 5.2. Such versions may be affected by several
buffer overflows.

To exploit these issues, an attacker would need the ability to upload
an arbitrary PHP script on the remote server, or to be able to
manipulate several variables processed by some PHP functions such as
htmlentities().

See also :

http://www.php.net/releases/5_2_0.php

Solution :

Upgrade to PHP version 5.2.0 or later.

/ CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
Created: 2008-12-29 13:11:36Last Changed: 2009-11-20 22:04:14
 
 The Complete Lexicon to Security