PT-2009-6202 · Php+1 · Php+1

Publicado

2009-11-27

·

Atualizado

2018-10-30

·

CVE-2009-4018

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.2.11 PHP versions 5.3.x prior to 5.3.1
Description The issue concerns the proc open function in PHP, which fails to enforce certain directives. This allows attackers to execute programs with an arbitrary environment via the env parameter. For example, a crafted value of the LD LIBRARY PATH environment variable can be used for exploitation.
Recommendations For PHP versions prior to 5.2.11, update to version 5.2.11 or later. For PHP versions 5.3.x prior to 5.3.1, update to version 5.3.1 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-4018
HPSBUX02543

Produtos afetados

Hp-Ux
Php