(SRPRE00002) phpSecurePages 0.23 beta

From: Asher Glynn (asherat_private)
Date: Mon Apr 23 2001 - 07:14:18 PDT

  • Next message: Matthew Rench: "Re: Bug in Cisco CBOS v2.3.0.053"

    =================================================
    Secure Reality Pty Ltd. Security Pre-Advisory #2 (SRPRE00002)
    http://www.securereality.com.au
    =================================================
    
    [Title]
    Remote command execution vulnerabilities in phpSecurePages
    
    [Released]
    23/4/2001
    
    This is a pre-release. This vulnerability will be discussed in detail during
    Shaun Clowes' speech at the Black Hat briefings in Asia in the week of the
    23rd of April. A full advisory will be issued following the conference
    
    [Vulnerable]
    phpSecurePages 0.23 beta
    
    All prior versions are almost certainly vulnerable but not tested
    
    [Impact]
    Remote command execution by unauthenticated remote users
    
    [Fix]
    The Authors have not yet been able to correct the issues in mainstream
    versions. SecureReality is providing patches for the problems, no liability
    for the performance or effectiveness of these patches is accepted.
    
    phpSecurePages 0.23 beta:
    http://www.securereality.com.au/patches/phpSecurePages-SecureReality.diff
    
    Users of earlier versions are advised to upgrade to the versions specified
    then apply the patches.
    
    To apply the patches:
     - cd to the directory in which the application files are stored (e.g
       /home/httpd/html/phpSecurePages/)
     - run 'patch -p0 < *Path to patch file*'
    
    [Disclaimer]
    Advice, directions and instructions on security vulnerabilities in this
    advisory do not constitute: an endorsement of illegal behavior; a guarantee
    that protection measures will work; an endorsement of any product or
    solution or recommendations on behalf of Secure Reality Pty Ltd. Content is
    provided as is and Secure Reality Pty Ltd does not accept responsibility for
    any damage or injury caused as a result of its use.
    



    This archive was generated by hypermail 2b30 : Mon Apr 23 2001 - 10:39:54 PDT