10.04.2006: Four new vulnerabilities in PHP found medium
heise online, the popular and well-known German IT news site, conveys four new vulnerabilities in the PHP script language. PHP is often used for web applications such as WordPress and many bulletin board systems like phpBB or vBulletin. The issues can be found in PHP versions up to (and including) 4.4.2 and 5.1.2, and the current CVS snapshots for the upcoming 5.1.3 release will be first to fix the issues. The first person who published the issues on his website and in the Full Disclosure mailing list is Maksymilian Arciemowicz. The four errors with different severity level are:
[Quelle]







