Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Apr 2008
    Location
    sanctum sanctorum
    Posts
    152

    Exclamation FYI if you are running PHP < 5.3.1

    if you allow file uploads this bugtraq posting may be of interest to you. I confirmed the DOS condition on one of my servers. Although the author does not provide a POC, not much imagination required to build a LFI from the description, though I did not test this.
    Last edited by thobarn; 11-22-2009 at 04:58 AM.

  2. #2
    BANNED
    Join Date
    Jun 2005
    Location
    Wild Wild West
    Posts
    2,025

    Lightbulb

    Thanks for that post, much appreciated. However, the flipside of the coin ...

    If you are running PHP > 5.3 then you might want to see this:

    PHP Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com

  3. #3
    Member
    Join Date
    Sep 2009
    Posts
    10

    Default

    does cpanel have a patch for the 5.2.11 vuln

  4. #4
    Member
    Join Date
    Jul 2009
    Posts
    68

    Default

    From what I've heard the PHP team will release 5.2.12 on thursday which fixes this problem.

  5. #5
    Member
    Join Date
    Sep 2009
    Posts
    10

    Default

    thx for reply

    question:

    does this mitigate flaw:

    SecurityFocus

    3. Install Suhosin PHP extension
    The Suhosin PHP extension has an option named "suhosin.upload.max_uploads".
    This option defines the maximum number of files that may be uploaded
    with one request and by default is set to 25.
    Suhosin PHP extension should not be confused with the Suhosin Patch
    which does not protect against this attack.


    edit php.ini to contain suhosin.upload.max_uploads = 25 ?

Similar Threads & Tags
Similar threads

  1. php.ini per dir with php running as cgi
    By vesko in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 04-18-2008, 09:39 AM
  2. FYI - Hotmail Blacklisted
    By nickp666 in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 06-25-2007, 11:42 AM
  3. FYI: Monsoon Users
    By Tom Pyles in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 06-05-2004, 07:44 PM
  4. FYI PHP sending HTML emails
    By misterb in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 12-04-2003, 04:48 PM
  5. FYI - Latest version of PHP (4.3.x) breaks phpNuke. Here's a fix
    By ecoutez in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 02-21-2003, 07:07 AM
Tags for this Thread
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube