VID |
22579 |
Severity |
30 |
Port |
80, ... |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
According to its banner, the version of PHP installed on the remote host is 5.4.x earlier than 5.4.12, and as such is potentially affected the following vulnerabilities :
- An error exists in the file 'ext/soap/soap.c' related to the 'soap.wsdl_cache_dir' configuration directive and writing cache files that could allow remote 'wsdl' files to be written to arbitrary locations. (CVE-2013-1635)
- An error exists in the file 'ext/soap/php_xml.c' related to parsing SOAP 'wsdl' files and external entities that could cause PHP to parse remote XML documents defined by an attacker. This could allow access to arbitrary files. (CVE-2013-1643)
Note: This check solely relied on the banner of the remote HTTP server to assess this vulnerability, so this might be a false positive.
* References: http://www.php.net/ChangeLog-5.php#5.4.12
* Platforms Affected: PHP Prior to 5.4.12 Any operating system Any version |
Recommendation |
Upgrade to the latest version of PHP (5.4.12 or later), available from the PHP Web site at http://www.php.net/ |
Related URL |
CVE-2013-1635,CVE-2013-1643 (CVE) |
Related URL |
58224,58766 (SecurityFocus) |
Related URL |
(ISS) |
|