Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Gentoo GLSA-200508-18 High: PhpWiki Command Execution Through XML-RPC

gentoo
Calendar Grey August 26, 2005
Scroller Gentoo
Critical security flaw identified in PhpWiki through XML-RPC remote commands. Gentoo users advised to update their systems immediately.
PhpWiki includes PHP XML-RPC code which is vulnerable to arbitrary command execution.

Summary

Gentoo Linux Security Advisory GLSA 200508-18 https://security.gentoo.org/ Severity: High Title: PhpWiki: Arbitrary command execution through XML-RPC Date: August 26, 2005 Bugs: #102380 ID: 200508-18

Synopsis ======= PhpWiki includes PHP XML-RPC code which is vulnerable to arbitrary command execution.
Background ========= PhpWiki is an application that creates a web site where anyone can edit the pages through HTML forms.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/phpwiki < 1.3.10-r2 >= 1.3.10-r2
========== Earlier versions of PhpWiki contain an XML-RPC library that improperly handles XML-RPC requests and responses with malformed nested tags.
Impa...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround