Get a Pentest and security assessment of your IT network.

2021-current

CVE-2014-4721 – The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 an

The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent attackers to obtain sensitive information from process memory by using the integer data type with crafted values, related to a “type confusion” vulnerability, as demonstrated by reading a private SSL key in an Apache HTTP Server web-hosting environment with mod_ssl and a PHP 5.3.x mod_php.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4721

Reference (s):

  • http://www-01.ibm.com/support/docview.wss?uid=swg21683486
  • http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
  • http://www.php.net/ChangeLog-5.php
  • https://bugs.php.net/bug.php?id=67498
  • DEBIAN:DSA-2974
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-4743 - Multiple cross-site scripting (XSS) vulnerabilities in (1) search_ajax.tp

2021-current

CVE-2014-9838 - magick/cache.c in ImageMagick 6.8.9-9 allows remote attackers to cause a

2021-current

CVE-2020-10447 - The way URIs are handled in admin/header.php in Chadha PHPKB Standard Mul