This alert was generated using only banner information. It may be a false positive.
Stefan Esser had discovered a weakness within the depths of the implementation of hashtables in the Zend Engine. This vulnerability affects a large number of PHP applications. It creates large new holes in many popular PHP applications. Additonally many old holes that were disclosed in the past were only fixed by using the unset() statement. Many of these holes are still open if the already existing exploits are changed by adding the correct numerical keys to survive the unset(). For a detailed explanation of the vulnerability read the referenced article.
Affected PHP versions (up to 4.4.2/5.1.3).
- Upgrade PHP to the latest version.
- WordPress Plugin All In One WP Security & Firewall SQL Injection (3.9.0)
- WordPress Plugin IGIT Posts Slider Widget 'src' Parameter Cross-Site Scripting (1.0)
- Drupal Core 7.x Multiple Vulnerabilities (7.0 - 7.28)
- WordPress Plugin Subscribe2 Cross-Site Scripting (10.15)
- WordPress Plugin CloudFlare Multiple Cross-Site Scripting Vulnerabilities (1.3.20)