SB2017101083 - Multiple vulnerabilities in PHP
Published: October 10, 2017 Updated: June 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2000-0860)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables.
2) Input validation error (CVE-ID: CVE-2000-0059)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.
Remediation
Install update from vendor's website.
References
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0455.html
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0477.html
- http://archives.neohapsis.com/archives/bugtraq/2000-09/0150.html
- http://cvsweb.php.net/viewcvs.cgi/php4/main/rfc1867.c.diff?r1=1.38%3Aphp_4_0_2&tr1=1.1&r2=text&tr2=1.45&diff_format=u
- http://www.securityfocus.com/bid/1649
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5190
- http://www.securityfocus.com/bid/911