Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.805688
Category:Web application abuses
Title:PHP Multiple Vulnerabilities - 01 (Jul 2015) - Windows
Summary:PHP is prone to multiple vulnerabilities.
Description:Summary:
PHP is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to:

- an integer overflow vulnerability in PHP's Calendar Extension Conversion
functions.

- a flaw in the cache directory that is due to the program creating files for
the cache in a predictable manner.

Vulnerability Impact:
Successfully exploiting this issue allow
remote attackers to inject WSDL files and have them be used in place of the
intended file and unexpected data result while using Calendar Extension
Conversion functions.

Affected Software/OS:
PHP versions through 5.6.7

Solution:
Update to PHP 5.6.8 or later.

CVSS Score:
4.6

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2015-1353
Common Vulnerability Exposure (CVE) ID: CVE-2013-6501
72530
http://www.securityfocus.com/bid/72530
GLSA-201606-10
https://security.gentoo.org/glsa/201606-10
SUSE-SU-2015:0436
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00003.html
http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html
https://bugzilla.redhat.com/show_bug.cgi?id=1009103
CopyrightCopyright (C) 2015 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.