Release date: 2012-03-10
Updated on: 2012-03-12
Affected Systems:
Zend Server 5.6.0
Description:
--------------------------------------------------------------------------------
Zend Server is a full enterprise Web application Server that runs and manages PHP applications.
The Zend Server and its components are returned to the user if they are not properly filtered when they are input through several parameters. arbitrary HTML and script code can be executed in the user's browser of the affected site.
<* Source: vendor
Link: http://packetstormsecurity.org/files/110642/Zend-Server-5.6.0-Script-Insertion.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Zend
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.zend.com/downloads