Home Page Catalogues Guides Blog
PHP (Hypertext Preprocessor) Info.

PHP (Hypertext Preprocessor) Info.

Exploit for Vulnerability in XML-RPC, PHP (Hypertext Preprocessor) Info.

Exploit for Vulnerability in XML-RPC

Exploit for Vulnerability in XML-RPC

July 6, 2005

US-CERT is aware of a working public exploit for a vulnerability in a common PHP extension module (XML-RPC) that could allow a remote attacker to execute code of their choosing on a vulnerable system. Any application, typically web-based, that uses a flawed XML-RPC PHP implementation is vulnerable to exploitation. XML-RPC allows software to make procedure calls over the Internet typically using HTTP and XML.
A remote attacker could exploit the XML-RPC vulnerability to execute PHP code of their choosing. The code would be executed in the context of the server program that runs the corresponding web-based application. More information about this vulnerability can be found in the following US-CERT Vulnerability Note:

VU#442845 - Multiple PHP XML-RPC implementations vulnerable to code injection: http://www.kb.cert.org/vuls/id/442845

US-CERT encourages administrators to apply the appropriate updates, patches, or fixes as soon as possible. If upgrading is not feasible or convenient at this time, then administrators should consider disabling the affected XML-RPC libraries.

- www.us-cert.gov

[ Comment, Edit or Article Submission ]

Share this:

Add To Del.icio.us Add To Reddit Add To Yahoo MyWeb Add To Google Bookmarks Add To Furl Fav This With Technorati Add To Newsvine Add To Bloglines Add To Ask Add To Windows Live Add To Slashdot Stumble This Digg This

More about:

Dec January 2009 Feb
Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31

PHP (Hypertext Preprocessor) Info. Blog on Technorati Related Blog of PHP (Hypertext Preprocessor) Info. on Sphere
 
Copyright © 2008 www.smbar.com. Blog | Sitemap | Advertise | Privacy | Disclaimer | Contact | Links