PHP Interpreter Direct Invocation Denial Of Service Vulnerability
BID:5280
Info
PHP Interpreter Direct Invocation Denial Of Service Vulnerability
| Bugtraq ID: | 5280 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 22 2002 12:00AM |
| Updated: | Jul 22 2002 12:00AM |
| Credit: | Discovery of this issue is credited to "Matthew Murphy" <[email protected]>. |
| Vulnerable: |
PHP PHP 4.2.2 PHP PHP 4.2.1 PHP PHP 4.2 .0 PHP PHP 4.1.2 PHP PHP 4.1.1 PHP PHP 4.1 .0 PHP PHP 4.0.7 RC3 PHP PHP 4.0.7 RC2 PHP PHP 4.0.7 RC1 PHP PHP 4.0.7 PHP PHP 4.0.6 PHP PHP 4.0.5 PHP PHP 4.0.4 PHP PHP 4.0.3 pl1 PHP PHP 4.0.3 PHP PHP 4.0.2 PHP PHP 4.0.1 pl2 PHP PHP 4.0.1 pl1 PHP PHP 4.0.1 PHP PHP 4.0 0 PHP PHP 3.0.18 PHP PHP 3.0.17 PHP PHP 3.0.16 PHP PHP 3.0.15 PHP PHP 3.0.14 PHP PHP 3.0.13 PHP PHP 3.0.12 PHP PHP 3.0.11 PHP PHP 3.0.10 PHP PHP 3.0.9 PHP PHP 3.0.8 PHP PHP 3.0.7 PHP PHP 3.0.6 PHP PHP 3.0.5 PHP PHP 3.0.4 PHP PHP 3.0.3 PHP PHP 3.0.2 PHP PHP 3.0.1 PHP PHP 3.0 0 PHP PHP 3.0 .16 PHP PHP 3.0 .13 PHP PHP 3.0 .12 PHP PHP 3.0 .11 PHP PHP 3.0 .10 |
| Not Vulnerable: | |
Discussion
PHP Interpreter Direct Invocation Denial Of Service Vulnerability
It is possible, under some circumstances, for remote attackers to invoke the PHP interpreter from the web. If the interpreter is invoked with no command line options, it will hang. Attackers may exploit this condition to cause a denial of service.
This is reported to be a problem with PHP and Apache on Microsoft Windows platforms. It may be possible to create this condition in other environments as well.
It is possible, under some circumstances, for remote attackers to invoke the PHP interpreter from the web. If the interpreter is invoked with no command line options, it will hang. Attackers may exploit this condition to cause a denial of service.
This is reported to be a problem with PHP and Apache on Microsoft Windows platforms. It may be possible to create this condition in other environments as well.
Exploit / POC
PHP Interpreter Direct Invocation Denial Of Service Vulnerability
The following example was submitted:
http://localhost/php/php
Additionally, the following exploit code was also provided by "Matthew Murphy" <[email protected]>:
The following example was submitted:
http://localhost/php/php
Additionally, the following exploit code was also provided by "Matthew Murphy" <[email protected]>:
Solution / Fix
PHP Interpreter Direct Invocation Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP Interpreter Direct Invocation Denial Of Service Vulnerability
References:
References: