HTTP: PHP Command Injection User Agent

This signature detects Web requests containing a potentially dangerous PHP script. A malicious site can exploit a known vulnerability in multiple PHP applications and execute arbitrary PHP commands on the victim's server.

Extended Description

phplist before 2.10.8 allows remote attackers to include files via unknown vectors, related to a "local file include vulnerability."

Affected Products

Tincan phplist

References

BugTraq: 32841

CVE: CVE-2008-5887

Short Name
HTTP:PHP:CMD-INJ-UA
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Agent CVE-2008-5887 Command Injection PHP User bid:32841
Release Date
03/22/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Tincan

CVSS Score

5.0

Found a potential security threat?