PHP 5.2.7 'magic_quotes_gpc' Security Bypass Weakness
BID:32673
Info
PHP 5.2.7 'magic_quotes_gpc' Security Bypass Weakness
| Bugtraq ID: | 32673 |
| Class: | Design Error |
| CVE: |
CVE-2008-5844 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 07 2008 12:00AM |
| Updated: | Jan 06 2010 12:12AM |
| Credit: | PHP |
| Vulnerable: |
PHP PHP 5.2.7 Gentoo Linux |
| Not Vulnerable: |
PHP PHP 5.2.8 |
Discussion
PHP 5.2.7 'magic_quotes_gpc' Security Bypass Weakness
PHP is prone to a security-bypass weakness.
Attackers can use this issue to bypass security checks in PHP applications that rely on the Magic Quotes functionality. This opens such applications up to potential attacks that take advantage of the software's failure to properly sanitize user input.
The issue affects PHP 5.2.7.
PHP is prone to a security-bypass weakness.
Attackers can use this issue to bypass security checks in PHP applications that rely on the Magic Quotes functionality. This opens such applications up to potential attacks that take advantage of the software's failure to properly sanitize user input.
The issue affects PHP 5.2.7.
Exploit / POC
PHP 5.2.7 'magic_quotes_gpc' Security Bypass Weakness
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
PHP 5.2.7 'magic_quotes_gpc' Security Bypass Weakness
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
PHP 5.2.7 'magic_quotes_gpc' Security Bypass Weakness
References:
References:
- Bug #42718 FILTER_UNSAFE_RAW not applied when configured as default filter, even (arnaud dot lb at gmail dot com)
- Bug #46759 magic_quotes_gpc doesn't work ([email protected])
- PHP 5.2.7 has been removed from distribution (PHP)
- PHP 5.2.8 Changelog (PHP)
- PHP Homepage (PHP)