Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHP MySQLI Error Logging Remote Format String Vulnerability

PHP is susceptible to a remote format string vulnerability in the 'mysqli' extension. This issue is due to a failure of the application to properly sanitize user-supplied input prior to using it in the format-specifier argument to a formatted printing function.

This issue allows attackers to execute arbitrary machine code in the context of the Web server hosting the PHP interpreter.

This issue affects PHP 5.1.0, and 5.1.1.







 

Privacy Statement
Copyright 2009, SecurityFocus