Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Gentoo: 202401-15 Alert: PHProjekt Vulnerability Remote Exploit Risk

gentoo
Calendar Grey December 30, 2004
Dist Gentoo Esm H88
The Gentoo Linux Security Advisory GLSA 200412-28 highlights a critical vulnerability in the PHProjekt application that allows remote code execution, along with necessary remediation steps.
PHProjekt contains a vulnerability that allows a remote attacker to execute arbitrary PHP code.

Summary

Gentoo Linux Security Advisory GLSA 200412-27 https://security.gentoo.org/ Severity: High Title: PHProjekt: Remote code execution vulnerability Date: December 30, 2004 Bugs: #75858 ID: 200412-27

Synopsis ======= PHProjekt contains a vulnerability that allows a remote attacker to execute arbitrary PHP code.
Background ========= PHProjekt is a modular groupware web application used to coordinate group activities and share files.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/phprojekt < 4.2-r2 >= 4.2-r2
========== cYon discovered that the authform.inc.php script allows a remote user to define the global variable $path_pre.
Impact ===== A remot...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/4092916_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here