Vietnam.vn - Nền tảng quảng bá Việt Nam

Two more security vulnerabilities have been discovered in the PHP programming language.

Báo Thanh niênBáo Thanh niên10/08/2023


According to Security Online , two new vulnerabilities in PHP have been discovered and assigned the identifiers CVE-2023-3823 and CVE-2023-3824. The CVE-2023-3823 vulnerability, with a CVSS index of 8.6, is an information disclosure vulnerability that allows remote attackers to obtain sensitive information from PHP applications.

This vulnerability stems from incomplete validation of user-provided XML input. An attacker can exploit it by sending a specially crafted XML file to the application. The application will then parse the code, allowing the attacker to access sensitive information, such as the contents of system files or the results of external requests.

The danger lies in the fact that any application, library, or server that parses or interacts with XML documents is vulnerable to this flaw.

Ngôn ngữ PHP bị phát hiện thêm 2 lỗ hổng bảo mật - Ảnh 1.

As a widely used programming language, PHP has serious security vulnerabilities.

Meanwhile, vulnerability CVE-2023-3824 is a buffer overflow vulnerability with a CVSS score of 9.4, allowing a remote attacker to execute arbitrary code on a PHP-based system. This vulnerability is caused by a PHP function improperly checking limits. An attacker can exploit it by sending a special request to the application, thereby causing a buffer overflow and gaining control of the system to execute arbitrary code.

Because of this danger, users are advised to update their systems to PHP version 8.0.30 as soon as possible. In addition, they should also take steps to protect PHP applications from attacks, such as authenticating all user input and using a web application firewall (WAF).



Source link

Comment (0)

Please leave a comment to share your feelings!

Same tag

Same category

A close-up view of the workshop making the LED star for Notre Dame Cathedral.
The 8-meter-tall Christmas star illuminating Notre Dame Cathedral in Ho Chi Minh City is particularly striking.
Huynh Nhu makes history at the SEA Games: A record that will be very difficult to break.
The stunning church on Highway 51 lit up for Christmas, attracting the attention of everyone passing by.

Same author

Heritage

Figure

Enterprise

Farmers in Sa Dec flower village are busy tending to their flowers in preparation for the Festival and Tet (Lunar New Year) 2026.

News

Political System

Destination

Product