PHP EXT/Filter FDF Post Filter Bypass Vulnerability
BID:22906
Info
PHP EXT/Filter FDF Post Filter Bypass Vulnerability
| Bugtraq ID: | 22906 |
| Class: | Design Error |
| CVE: |
CVE-2007-1452 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2007 12:00AM |
| Updated: | May 12 2015 07:33PM |
| Credit: | Stefan Esser is credited with the discovery of this vulnerability. |
| Vulnerable: |
PHP PHP 5.1.6 PHP PHP 5.1.5 PHP PHP 5.1.4 PHP PHP 5.1.3 -RC1 PHP PHP 5.1.3 PHP PHP 5.1.2 PHP PHP 5.1.1 PHP PHP 5.1 PHP PHP 5.0.5 PHP PHP 5.0.4 PHP PHP 5.0.3 PHP PHP 5.0.2 PHP PHP 5.0.1 PHP PHP 5.0 candidate 3 PHP PHP 5.0 candidate 2 PHP PHP 5.0 candidate 1 PHP PHP 5.0 .0 PHP PHP 5.2 |
| Not Vulnerable: | |
Discussion
PHP EXT/Filter FDF Post Filter Bypass Vulnerability
The PHP ext/filter content filter is prone to a filter-bypass vulnerability.
Successful exploitation can allow an attacker to bypass the security filter responsible for blocking potentially malicious content.
Attackers can exploit this issue to inject malicious content in PHP applications that use the vulnerable filter.
The PHP ext/filter content filter is prone to a filter-bypass vulnerability.
Successful exploitation can allow an attacker to bypass the security filter responsible for blocking potentially malicious content.
Attackers can exploit this issue to inject malicious content in PHP applications that use the vulnerable filter.
Exploit / POC
PHP EXT/Filter FDF Post Filter Bypass Vulnerability
The following proof-of-concept exploit is available:
The following proof-of-concept exploit is available:
Solution / Fix
PHP EXT/Filter FDF Post Filter Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PHP EXT/Filter FDF Post Filter Bypass Vulnerability
References:
References:
- MOPB-17-2007:PHP ext/filter FDF Post Bypass Vulnerability (Stefan Esser)
- PHP Homepage (PHP)