PDA

View Full Version : Serious PHP Vulnerability Reported



Ben
July 24th, 2002, 21:16
Webhosts might want to check this article (http://www.theregister.co.uk/content/55/26316.html) out at The Register


Quoted from the original article at The Register
"...The PHP form-data POST handler is susceptible to a malicious POST request that can trigger an error condition which, depending on your hardware, can crash the machine or provide for remote exploitation..."


(If this belongs in the computer forum, would a mod please move it. --Ben)

atlas
July 25th, 2002, 15:48
Any responsible webhost would be at the very least be subscribed to CERT alerts which posted this a while ago. Bugtraq is a far better source, but not everyone has time to read that.