Unconfigured Ad Widget

Collapse

0-Day PHP-CGI bug/exploit in the open

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • ocabj
    Calguns Addict
    • Oct 2005
    • 7924

    0-Day PHP-CGI bug/exploit in the open

    There is a PHP-CGI bug that allows for remote code execution. It affects up to and including the current release of the 5 branch. PHP 5.3.12 and 5.4.2 were released to patch the bug.



    We just got wind of this an hour or so ago and have been mitigating this bug on all of our web servers running PHP in the event someone uses mod_cgi for PHP.

    Also, if you have your own hosted domain, odds are that you are vulnerable if it allows php-cgi. There is a method to mitigate the bug on your domain's virtual host even if you don't have root access on your web server.
    Last edited by ocabj; 05-03-2012, 8:42 PM.

    Distinguished Rifleman #1924
    NRA Certified Instructor (Rifle and Metallic Cartridge Reloading) and RSO
    NRL22 Match Director at WEGC

    https://www.ocabj.net
Working...
UA-8071174-1