Snort-alerts/WEB-PHP-Setup-php-access

From aldeid
Jump to navigation Jump to search

WEB-PHP Setup.php access

Trigger

This event indicates that an attempt may have been made to exploit a known vulnerability in the PHP application MediaWiki . This application does not perform stringent checks when handling user input, this may lead to the attacker being able to execute PHP code and include php files of the attackers choosing.

Affected systems

  • MediaWiki MediaWiki-stable 20031107
  • MediaWiki MediaWiki-stable 20030829

Impact

Possible execution of arbitrary code and unauthorized administrative access to the target system.

False positives

None known

Scenario

An attacker can exploit weaknesses to gain access as the administrator by supplying input of their choosing to the underlying PHP script.

Example

INCOMPLETE SECTION OR ARTICLE
This section/article is being written and is therefore not complete.
Thank you for your comprehension.

Corrective actions

Ensure the system is using an up to date version of the software.