PT-2007-2702 · Php · Php
Publicado
2007-03-06
·
Atualizado
2011-03-08
·
CVE-2007-1287
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PHP versions 4.4.3 through 4.4.6
PHP version 6.0 in CVS
Description
The issue allows remote attackers to conduct cross-site scripting (XSS) attacks via GET, POST, or COOKIE array values, which are not escaped in the phpinfo output. This could enable a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
Recommendations
For PHP versions 4.4.3 through 4.4.6, consider disabling the phpinfo function until a patch is available.
For PHP version 6.0 in CVS, restrict access to the phpinfo output to minimize the risk of exploitation.
Avoid using user-supplied arrays in GET, POST, or COOKIE variables upon submission to phpinfo() until the issue is resolved.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Php