Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.53640
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 351-1 (php4)
Summary:The remote host is missing an update to php4;announced via advisory DSA 351-1.
Description:Summary:
The remote host is missing an update to php4
announced via advisory DSA 351-1.

Vulnerability Insight:
The transparent session ID feature in the php4 package does not
properly escape user-supplied input before inserting it into the
generated HTML page. An attacker could use this vulnerability to
execute embedded scripts within the context of the generated page.

For the stable distribution (woody) this problem has been fixed in
version 4:4.1.2-6woody3.

For the unstable distribution (sid) this problem will be fixed soon.
Refer to Debian bug #200736.

We recommend that you update your php4 package.

Solution:
Please install the updated package(s).

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2003-0442
BugTraq ID: 7761
http://www.securityfocus.com/bid/7761
Bugtraq: 20030530 PHP Trans SID XSS (Was: New php release with security fixes) (Google Search)
http://marc.info/?l=bugtraq&m=105449314612963&w=2
Bugtraq: 20030707 [OpenPKG-SA-2003.032] OpenPKG Security Advisory (php) (Google Search)
http://marc.info/?l=bugtraq&m=105760591228031&w=2
Computer Incident Advisory Center Bulletin: N-112
http://www.ciac.org/ciac/bulletins/n-112.shtml
Conectiva Linux advisory: CLSA-2003:691
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000691
Debian Security Information: DSA-351 (Google Search)
http://www.debian.org/security/2003/dsa-351
http://www.mandriva.com/security/advisories?name=MDKSA-2003:082
http://shh.thathost.com/secadv/2003-05-11-php.txt
http://www.osvdb.org/4758
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A485
http://www.redhat.com/support/errata/RHSA-2003-204.html
SCO Security Bulletin: CSSA-2003-SCO.28
http://www.securitytracker.com/id?1008653
TurboLinux Advisory: TLSA-2003-47
http://www.turbolinux.co.jp/security/2003/TLSA-2003-47j.txt
XForce ISS Database: php-session-id-xss(12259)
https://exchange.xforce.ibmcloud.com/vulnerabilities/12259
CopyrightCopyright (C) 2008 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.