Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

PHP 'openssl_encrypt()' Function Information Disclosure Vulnerability (Windows)

Information

Severity

Severity

Medium

Family

Family

Web application abuses

CVSSv2 Base

CVSSv2 Base

5.0

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

Solution Type

Solution Type

Vendor Patch

Created

Created

11 years ago

Modified

Modified

5 years ago

Summary

This host is installed with PHP and is prone to information disclosure vulnerability

Insight

Insight

The flaw is due to error in 'openssl_encrypt()' function when handling empty $data strings which will allow an attacker to gain access to arbitrary pieces of information in current memory.

Affected Software

Affected Software

PHP version 5.3.9 through 5.3.13 on Windows

Solution

Solution

Apply the patch or upgrade to the latest version from the references. ***** NOTE: Ignore this warning, if above mentioned patch is manually applied. *****

Common Vulnerabilities and Exposures (CVE)