vendor:
by:
Unknown (advisory cut from /str0ke)
7.5
CVSS
HIGH
Buffer Overflow
Unknown
CWE
Product Name:
Affected Version From: PHP versions 4.3.10
Affected Version To: PHP versions 4.4.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
Unknown
PHP Windows XP SP1 EIP Overwrite Exploit
This exploit is designed to work with PHP versions 4.3.10 and 4.4.0 under Windows XP SP 1. It overwrites the EIP (Extended Instruction Pointer) with a CALL ESI from ws2_32.dll from Windows XP SP1. The shellcode is written into the $user variable and a temporary memory location is trashed. This exploit is specifically for Apache/1.3.33 and PHP/4.4.0 on Windows only.
Mitigation:
Unknown