Rapid7 Vulnerability & Exploit Database

HP-UX: CVE-2009-4017: Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)

Free InsightVM Trial No credit card necessary
Watch Demo See how it all works
Back to Search

HP-UX: CVE-2009-4017: Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
11/23/2009
Created
07/25/2018
Added
08/11/2017
Modified
09/12/2017

Description

PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier for remote attackers to exploit local file inclusion vulnerabilities, via multiple requests, related to lack of support for the max_file_uploads directive.

Solution(s)

  • hpux-update-hpuxws22apache-php
  • hpux-update-hpuxws22apache-php2
  • hpux-update-hpuxws22apch32-php
  • hpux-update-hpuxws22apch32-php2
  • hpux-update-hpuxwsapache-php
  • hpux-update-hpuxwsapache-php2
  • hpux-update-hpuxwsapch32-php
  • hpux-update-hpuxwsapch32-php2

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;