SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow World Laboratory of Bugtraq Database

Arrow  Topic :

eAccelerator encoder files backup Vulnerability


Arrow  WLB : WLB-2009070004  (About)
Arrow  SecurityAlert : 6027
Arrow  Date : 2009-07-03
Arrow  Credit          : linuxrootkit2008
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote : Yes
Arrow  Local     : No
Arrow  Status   : Bug

Arrow  History : [2009-07-03] Started

Arrow  Affected software :  eAccelerator encoder



Arrow  Text :  

eAccelerator encoder files backup Vulnerability

1.Description

eAccelerator is a free open-source PHP accelerator, optimizer, and dynamic
content cache. It increases the performance of PHP scripts by caching them
in their compiled state, so that the overhead of compiling is almost
completely eliminated. It also optimizes scripts to speed up their
execution. eAccelerator typically reduces server load and increases the
speed of your PHP code by 1-10 times.

2. The Vulnerability

eAccelerator has a function which encode php source in encoder.php.

You can backup all system files to specify directory or specify files.Of
course you can upload image to Web Server and backup it to the web
directory

so you can ...........

3.II. Disclosure Timeline

2009/06/29 Vendor contact.

2009/06/30 Public Disclosure.

4. Thanks

all of Whitehat Community's friend && Great Milw0rm!

2009/06/30 by cnbird

Sorry my bad english!



Audyt bezpieczeństwa

Security Audit

Analiza powłamaniowa


If you want change this note, please use UCP



Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

Copyright © SecurityReason.com. All Rights Reserved.