HZNQ.COM
welcome to my space
X
Wellness | Real Estate | Press Releases | Trucks | Career Management | Furniture | Health and Safety | Computer Forensics | Related articles
Welcome to:hznq.com
Article search:  
NAVIGATION - HOME
PHP Zaps Security Leaks
Published by: jack 2008-08-22

The open-source PHP Group has released a fix for a pair of security holes that could be exploited to execute arbitrary code on remote PHP servers.

The flaws affect PHP versions 4.3.7 and prior and version 5.0.0RC3 and prior. The final version of PHP 5.0, which was released earlier this week, is not affected.

Fixes have been included in the updated PHP 4.3.8, and the PHP Group is strongly encouraging users to upgrade.

According to research firm Secunia, the flaws carry a "highly critical" rating, because it could allow malicious attackers to seize control of vulnerable servers and use a Web browser to launch dangerous code.

Advocacy Project Blogs - All Blogs - Archives for: July 2007::
Farmers Struggle for Food Security in Eastern Nepal. The summer of meetings nepalnews.com/archive/2007/jul/jul28/news01.php. Leave a comment • Trackback (0)
http://advocacynet.org/blogs/index.php?blog=1&m=200707
HOME

The flaws were discovered by E-matters researcher Stefan Esser during a re-audit of the PHP code. Esser posted an alert online to warn that the vulnerabilities affect PHP servers with activated "memory_limit."

"During a re-audit of the memory_limit problematic it was discovered that it is possible for a remote attacker to trigger the memory_limit request termination in places where an interruption is unsafe. This can be abused to execute arbitrary code on remote PHP servers," the researcher warned.

Essert said the more serious of the two bugs was "quite easy to exploit" and is exploitable on any platform.

The second flaw was found in PHP's "strip_tags()" function that fails to strip obfuscated HTML tags. Essert said the hole could be exploited to conduct cross-site scripting attacks against sites, which only rely on the "strip_tags()" functionality to prevent such attacks.

PHP is a general-purpose scripting language that is backed by the open-source Apache Project. It is shipping standard with a number of Linux-powered Web servers as an Apache module and has enjoyed startling usage growth over the last four years. According to Netcraft statistics for June 2004, PHP is currently in use on at least 16 million domains.




Pre-Article:Bill Fills Phishing Holes
Next-Article:Identity Theft Law Hits Back at 'Phishers'
You are looking at:hznq.com's PHP Zaps Security Leaks, click hznq.com to home
#If you have any other info about this subject , Please add it free.#
Your name:
E-mail:
Telphone:

Your comments:


If you have any other info aboutPHP Zaps Security Leaks, Please add it free.
  • Forrester: IT Help Could be Better
  • CMGI Takes Stake in Netcentives
  • Intel Debuts First WiMAX Chip
  • Wily Readies Customer Experience Manager Update
  • CDnow Launches Proprietary Customer Rewards Program
  • The Conference Call Is Dead
  • A Wily Agent to Troubleshoot
  • Report: Business-to-Consumer Sites to Spend $552 Million in 1998
  • ARM Hangs Designs on Multicore Chip
  • Incamail Aims at ISPs With Free DEA Offering
  • MP3.com Offers Free Digital CDs
  • PurchasePro.com, Sprint In E-Commerce Pact
  • Ellison's Absence A Buzzkill For Security Show
  • AMD Launches Athlons for Desktop, Mobile
  •  
  • CheckFree, Southern Co. Team Up For Online Payments
  • BEA, IBM Dominate App Server Software Market
  • DRM Becomes a Balancing Act
  • Only a Third of Surfers Are Shoppers, Study Finds
  • Intel Patent Aims to Stop Overclocking
  • Priceline Continues Expansion
  • 'Virtual Climate Time Machine' in the Cards for IBM
  • Gateway Taps IBM for Tech Support
  • Punch Networks Partners with IBM
  • Akamai Scores With Expanded Terra Lycos Deal
  • More Companies to Use Internet for Purchasing
  • Chris Stone, CEO, StreamServe
  • New Intel Platforms 'Sooner Than You Think'?
  • About us |Contact us |Advertisement |Site map |Exchange links
    Copyright© 2008hznq.com All Rights Reserved