Skip to main content

PHP Multiple Vulnerabilities

Last Update Date: 17 Sep 2018 10:42 Release Date: 17 Sep 2018 4360 Views

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

Multiple vulnerabilities have been identified in PHP, a remote attacker can exploit these vulnerabilities to perform remote code execution, security restriction bypass, disclose sensitive information, spoofing and tampering on the targeted system.


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure
  • Spoofing
  • Data Manipulation

System / Technologies affected

  • PHP 7.2 prior to 7.2.10
  • PHP 7.1 prior to 7.1.22
  • PHP 7.0 prior to 7.0.32
  • PHP 5.6 prior to 5.6.38

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

 

The vendor has issued a fix:

  • PHP 7.2: 7.2.10
  • PHP 7.1: 7.1.22
  • PHP 7.0: 7.0.32
  • PHP 5.6: 5.6.38

 


Vulnerability Identifier

  • No CVE information is available

Source


Related Link