Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-0057

Опубликовано: 11 янв. 2012
Источник: redhat
CVSS2: 6.4

Описание

PHP before 5.3.9 has improper libxslt security settings, which allows remote attackers to create arbitrary files via a crafted XSLT stylesheet that uses the libxslt output extension.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4phpWill not fix
Red Hat Enterprise Linux 5phpFixedRHSA-2012:104527.06.2012
Red Hat Enterprise Linux 5php53FixedRHSA-2012:104727.06.2012
Red Hat Enterprise Linux 6phpFixedRHSA-2012:104627.06.2012

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=782657php: XSLT file writing vulnerability

6.4 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

PHP before 5.3.9 has improper libxslt security settings, which allows remote attackers to create arbitrary files via a crafted XSLT stylesheet that uses the libxslt output extension.

nvd
больше 14 лет назад

PHP before 5.3.9 has improper libxslt security settings, which allows remote attackers to create arbitrary files via a crafted XSLT stylesheet that uses the libxslt output extension.

debian
больше 14 лет назад

PHP before 5.3.9 has improper libxslt security settings, which allows ...

github
около 4 лет назад

PHP before 5.3.9 has improper libxslt security settings, which allows remote attackers to create arbitrary files via a crafted XSLT stylesheet that uses the libxslt output extension.

CVSS3: 4.8
fstec
больше 14 лет назад

Уязвимость библиотеки libxslt интерпретатора языка программирования PHP, позволяющая нарушителю создать произвольные файлы

6.4 Medium

CVSS2