Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2002-1954

Опубликовано: 31 дек. 2002
Источник: debian

Описание

Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php4not-affectedpackage
php5fixed5.1.1-1package

Примечания

  • According to https://bugs.php.net/bug.php?id=19881 this only affects a

  • php function that displays the PHP logo and version information. In the bug

  • log the developers seem unwilling to fix this, as it only affects a debug

  • function.

  • can not reproduce in any versions of php4 in the archive.

Связанные уязвимости

nvd
больше 22 лет назад

Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php.

github
около 3 лет назад

Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php.