phpWebSite is vulnerable to the remote execution of arbitrary PHP script code and to other, yet undisclosed, vulnerabilities.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200507-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: phpWebSite: Multiple vulnerabilities Date: July 10, 2005 Bugs: #97461 ID: 200507-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= phpWebSite is vulnerable to the remote execution of arbitrary PHP script code and to other, yet undisclosed, vulnerabilities. Background ========= phpWebSite is a content management system written in PHP. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/phpwebsite < 0.10.1-r1 > = 0.10.1-r1 Description ========== phpWebSite fails to sanitize input sent to the XML-RPC server using the "POST" method. Other unspecified vulnerabilities have been discovered by Diabolic Crab of Hackers Center. Impact ===== A remote attacker could exploit the XML-RPC vulnerability to execute arbitrary PHP script code by sending specially crafted XML data to phpWebSite. The undisclosed vulnerabilities do have an unknown impact. Workaround ========= There is no known workaround at this time. Resolution ========= All phpWebSite users should upgrade to the latest available version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-app/phpwebsite-0.10.1-r1" References ========= [ 1 ] CAN-2005-1921 [ 2 ] phpWebSite announcement ;ANN_user_op=view&ANN_id=989 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200507-07 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
phpwebsite contains an sql injection vulnerability in the calendarmodule which allows the attacker to execute sql queries.. - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200309-03 - - --------------------------------------------------------------------- PACKAGE : phpwebsite SUMMARY : SQL Injection, DoS and XSS Vulnerabilities DATE : 2003-09-02 08:54 UTC EXPLOIT : remote VERSIONS AFFECTED : =phpwebsite-0.9.3_p1 CVE : - - --------------------------------------------------------------------- phpwebsite contains an sql injection vulnerability in the calendar module which allows the attacker to execute sql queries. In addition phpwebsite is also vulnerable to XSS, more information can be found in the full advisory. Read the full advisory at: http://marc.theaimsgroup.com/?l=bugtraq&m=106062021711496&w=2 SOLUTION It is recommended that all Gentoo Linux users who are running net-www/phpwebsite upgrade to phpwebsite-0.9.3_p1 as follows: emerge sync emerge phpwebsite emerge clean - - ---------------------------------------------------------------------
Get the latest Linux and open source security news straight to your inbox.