Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Gentoo: 200705-16 Critical Risk for Remote Execution in PhpWiki Software

gentoo
Calendar Grey May 17, 2007
Dist Gentoo Esm H88
Recent findings highlight a critical vulnerability in PhpWiki that permits remote code execution on Gentoo platforms. It is paramount to secure your environment promptly.
A vulnerability has been discovered in PhpWiki allowing for the remote execution of arbitrary code.

Summary

Gentoo Linux Security Advisory GLSA 200705-16 https://security.gentoo.org/ Severity: High Title: PhpWiki: Remote execution of arbitrary code Date: May 17, 2007 Bugs: #174451 ID: 200705-16

Synopsis ======= A vulnerability has been discovered in PhpWiki allowing for the remote execution of arbitrary code.
Background ========= PhpWiki is an open source content management system written in PHP.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/phpwiki < 1.3.10-r3 >= 1.3.10-r3
========== Harold Hallikainen has reported that the Upload page fails to properly check the extension of a file.
Impact ===== A remote attacker could upload a specially crafted PHP file...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3760007_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here