PHPIDS 'unserialize()' PHP Code Execution Vulnerability
BID:41954
Info
PHPIDS 'unserialize()' PHP Code Execution Vulnerability
| Bugtraq ID: | 41954 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2009 12:00AM |
| Updated: | Dec 09 2009 12:00AM |
| Credit: | Stefan Esser |
| Vulnerable: |
PHPIDS Team PHPIDS 0.6.2 |
| Not Vulnerable: |
PHPIDS Team PHPIDS 0.6.3 1 |
Discussion
PHPIDS 'unserialize()' PHP Code Execution Vulnerability
PHPIDS is prone to a vulnerability that lets remote attackers execute arbitrary code because the application fails to sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected webserver process.
PHPIDS versions prior to and including 0.6.2 are vulnerable.
PHPIDS is prone to a vulnerability that lets remote attackers execute arbitrary code because the application fails to sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected webserver process.
PHPIDS versions prior to and including 0.6.2 are vulnerable.
Exploit / POC
PHPIDS 'unserialize()' PHP Code Execution Vulnerability
Attackers may exploit this issue through a browser.
Attackers may exploit this issue through a browser.
Solution / Fix
PHPIDS 'unserialize()' PHP Code Execution Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
PHPIDS 'unserialize()' PHP Code Execution Vulnerability
References:
References:
- Vendor Homepage (PHPIDS)
- PHPIDS Unserialize() Vulnerability (PHPIDS)