Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Gentoo: GLSA 200508-21 High: phpWebSite SQL Injection and Execution

gentoo
Calendar Grey August 31, 2005
Scroller Gentoo
The Gentoo GLSA 202309-45 highlights a critical flaw in phpWebSite that permits unauthorized command execution and facilitates SQL injection attacks.
phpWebSite is vulnerable to multiple issues which result in the execution of arbitrary code and SQL injection.

Summary

Gentoo Linux Security Advisory GLSA 200508-21 https://security.gentoo.org/ Severity: High Title: phpWebSite: Arbitrary command execution through XML-RPC and SQL injection Date: August 31, 2005 Bugs: #102785 ID: 200508-21

Synopsis ======= phpWebSite is vulnerable to multiple issues which result in the execution of arbitrary code and SQL injection.
Background ========= phpWebSite is a web site content management system.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/phpwebsite < 0.10.2_rc2 >= 0.10.2_rc2
========== phpWebSite uses an XML-RPC library that improperly handles XML-RPC requests and responses with malformed nested tags. Furthermore, "ma...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround