CVE-2010-3870
CVE-2010-3870
The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.
Produtos afetados
n/a · n/aPoCs públicas encontradas — 1
exploitdbwww.exploit-db.com/exploits/34950não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://bugs.php.net/bug.php?id=48230http://bugs.php.net/bug.php?id=49687http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-January/052836.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-January/052845.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.htmlhttp://marc.info/?l=bugtraq&m=133469208622507&w=2http://secunia.com/advisories/42410http://secunia.com/advisories/42812http://sirdarckcat.blogspot.com/2009/10/couple-of-unicode-issues-on-php-and.htmlhttp://support.apple.com/kb/HT4581http://svn.php.net/viewvc?view=revision&revision=304959