FreeBSD : phpmyfaq -- Remote PHP Code Execution Vulnerability (c80a3d93-8632-11e1-a374-14dae9ebcf89)

high Nessus Plugin ID 58757

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

The phpMyFAQ project reports :

The bundled ImageManager library allows injection of arbitrary PHP code to execute arbitrary PHP code and upload malware and trojan horses.

Solution

Update the affected package.

See Also

https://www.phpmyfaq.de/news/14

http://www.nessus.org/u?f7e9fabe

Plugin Details

Severity: High

ID: 58757

File Name: freebsd_pkg_c80a3d93863211e1a37414dae9ebcf89.nasl

Version: 1.7

Type: local

Published: 4/16/2012

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:phpmyfaq, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 4/14/2012

Vulnerability Publication Date: 4/14/2012