PHP Multiple Functions Reference Parameter Information Disclosure Vulnerability
BID:23202
Info
PHP Multiple Functions Reference Parameter Information Disclosure Vulnerability
| Bugtraq ID: | 23202 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 29 2007 12:00AM |
| Updated: | Mar 30 2007 03:33PM |
| Credit: | Stefan Esser is credited with the discovery of this vulnerability. |
| Vulnerable: |
PHP PHP 5.2.1 PHP PHP 5.1.6 PHP PHP 5.1.5 PHP PHP 5.1.4 PHP PHP 5.1.3 -RC1 PHP PHP 5.1.3 PHP PHP 5.1.2 PHP PHP 5.1.1 PHP PHP 5.1 PHP PHP 5.0.5 PHP PHP 5.0.4 PHP PHP 5.0.3 PHP PHP 5.0.2 PHP PHP 5.0.1 PHP PHP 5.0 candidate 3 PHP PHP 5.0 candidate 2 PHP PHP 5.0 candidate 1 PHP PHP 5.0 .0 PHP PHP 4.4.6 PHP PHP 4.4.5 PHP PHP 4.4.4 PHP PHP 4.4.3 PHP PHP 4.4.2 PHP PHP 4.4.1 PHP PHP 4.4 .0 PHP PHP 4.3.11 PHP PHP 4.3.10 PHP PHP 4.3.9 PHP PHP 4.3.8 PHP PHP 4.3.7 PHP PHP 4.3.6 PHP PHP 4.3.5 PHP PHP 4.3.4 PHP PHP 4.3.3 PHP PHP 4.3.2 PHP PHP 4.3.1 PHP PHP 4.3 PHP PHP 4.2.3 PHP PHP 4.2.2 PHP PHP 4.2.1 PHP PHP 4.2 .0 PHP PHP 4.2 -dev PHP PHP 4.1.2 PHP PHP 4.1.1 PHP PHP 4.1 .0 PHP PHP 4.0.7 RC3 PHP PHP 4.0.7 RC2 PHP PHP 4.0.7 RC1 PHP PHP 4.0.7 PHP PHP 4.0.6 PHP PHP 4.0.5 PHP PHP 4.0.4 PHP PHP 4.0.3 pl1 PHP PHP 4.0.3 PHP PHP 4.0.2 PHP PHP 4.0.1 pl2 PHP PHP 4.0.1 pl1 PHP PHP 4.0.1 PHP PHP 4.0 0 PHP PHP 5.2 |
| Not Vulnerable: | |
Discussion
PHP Multiple Functions Reference Parameter Information Disclosure Vulnerability
PHP is prone to an information-disclosure vulnerability due to a design error.
The vulnerability resides in various functions that accept parameters as references.
Successful exploits will allow attackers to obtain sensitive information. Information harvested may assist on further attacks.
PHP 4 through 4.4.6 and 5 through 5.2.1 are affected.
PHP is prone to an information-disclosure vulnerability due to a design error.
The vulnerability resides in various functions that accept parameters as references.
Successful exploits will allow attackers to obtain sensitive information. Information harvested may assist on further attacks.
PHP 4 through 4.4.6 and 5 through 5.2.1 are affected.
Exploit / POC
PHP Multiple Functions Reference Parameter Information Disclosure Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
PHP Multiple Functions Reference Parameter Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
PHP Multiple Functions Reference Parameter Information Disclosure Vulnerability
References:
References:
- MOPB-37-2007:PHP iptcembed() Interruption Information Leak Vulnerability (Stefan Esser)
- PHP Homepage (PHP)