Web Service Protocol Security Vulnerabilities

Source: Internet
Author: User
Tags pear

Two Security Vulnerabilities discovered in a Web service protocol may allow attackers to control vulnerable servers.

The vulnerabilities found in XML-RPC For PHP and PEAR XML_RPC affect a large number of Web applications, according to a security bulletin from GulfTech, the company that found the vulnerability.

XML-based Remote Procedure Call (RPC) systems, such as XML-RPC, work together with HTTP to drive Web services. XML-RPC For PHP and PEAR XML_RPC are used to implement XML-RPC For the PHP scripting language.

According to GulfTech, this protocol is called PHPXMLRPC and is used in many popular Web applications, such as PostNuke, Drupal, b2evolution, and TikiWiki.

GulfTech said: "PHPXMLRPC has a very dangerous PHP code execution vulnerability that may allow attackers to destroy vulnerable Web servers ."

GulfTech says the vulnerability is caused by an eval () call to the parseRequest () function of the XMLRPC server that the component fails to normally inspect. By creating an XML file that uses single quotes to access eval () calls, attackers can easily execute PHP code on the target server.

The latest PHPXMLRPC version has solved this problem. For applications that use this component, such as eGroupWare and phpGroupWare, the security vendor Secunia recommends limiting access to the XML-RPC functionality.

According to Gulftech, the vulnerability in PEAR XML_RPC is related to the vulnerability in PHPXMLRPC. However, the vulnerability may damage vulnerable servers. The new version 1.3.1 has solved this problem.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.