PHP 5.4.x < 5.4.12 Multiple Vulnerabilities
Medium Nessus Network Monitor Plugin ID 6708
SynopsisThe remote web server uses a version of PHP that is affected by multiple vulnerabilities.
DescriptionPHP versions 5.4.x earlier than 5.4.12 are affected by the following vulnerabilities :
- An error exists in the file 'ext/soap/soap.c' related to the 'soap.wsdl_cache_dir' configuration directive and writing cache files that could allow remote 'wsdl' files to be written to arbitrary locations. (CVE-2013-1635)
- An error exists in the file 'ext/soap/php_xml.c' related to parsing SOAP 'wsdl' files and external entities that could cause PHP to parse remote XML documents defined by an attacker. This could allow access to arbitrary files. (CVE-2013-1643)
SolutionUpgrade to PHP version 5.4.12 or later.