On the PHPClasses.org blog there's a new post detailing an issue that came up in the PHP 5.3.9 release that caused a large security issue (PHP 5.3.10 has, however, already been released to correct the issue).
code executionPHPClasses.org: Another Serious Security Bug on PHP 5.3.9PHPDeveloper.org Mon, 02/06/2012 - 14:16
On the PHPClasses.org blog there's a new post detailing an issue that came up in the PHP 5.3.9 release that caused a large security issue (PHP 5.3.10 has, however, already been released to correct the issue). Anson Cheung's Blog: Top 10 PHP Best Security Practices for Sys ...PHPDeveloper.org Mon, 01/30/2012 - 14:52
In this recent post to his blog Anson Cheung provides a set of helpful hints for sysadmins to follow when installing (or just securing) the PHP installations on their systems. DZone.com: Hardening PHP: How to securely include remote code (p...PHPDeveloper.org Fri, 06/10/2011 - 09:28
On the PHP on Windows blog from DZone.com Krzysztof Kotowicz has a new post - part one in a series on securing your PHP application - a look at securely including remote code from a source outside of your application. Microsoft's May Security Patch Is Light After Massive Load in Ap...Redmond Developer News | News Mon, 05/09/2011 - 16:41
The May Security Bulletins address remote code execution vulnerabilities in Windows Server and Microsoft Office. Microsoft's March Security Update Doesn't Address MHTML FlawRedmond Developer News | News Fri, 03/11/2011 - 18:41
The March security patch, released on Tuesday, addresses four vulnerabilities related to remote code execution exploits in Windows and related applications. Adobe warns of critical Flash Player flawsLinux Today Thu, 08/12/2010 - 03:06
ZDNet: "Adobe's ubiquitous Flash Player software is vulnerable to at least six critical security vulnerabilities that could allow hackers to launch remote code execution attacks, the company warned in an advisory." MOPS-2010-035: e107 BBCode Remote PHP Code Execution Vulnerabili...Planet PHP Wed, 05/19/2010 - 02:25
It was discovered that access control to the [php] bbcode which allows executing PHP code is wrongly implemented in e107. Affected versions Affected is e107 <= 0.7.20 Risk Highly Critical. Credits The vulnerability was discovered by Stefan Esser. MOPS-2010-030: CMSQlite mod Parameter Local File Inclusion Vulne...Planet PHP Sat, 05/15/2010 - 14:58
A local file inclusion vulnerability was discovered in CMSQlite that might allow remote PHP code execution. Affected versions Affected is CMSQlite <= 1.2 Risk Critical. Credits The vulnerability was discovered by Stefan Esser as part of the SQL Injection Marathon. PowerPoint Security Bug Found in Office 2003Redmond Developer News | News Fri, 04/03/2009 - 17:42
A new zero-day remote code execution vulnerability has come to Redmond's attention, this time affecting Microsoft Office PowerPoint. Excel Bug Prompts Microsoft AdvisoryRedmond Developer News | News Wed, 02/25/2009 - 04:16
Microsoft is looking into public reports of a new-found vulnerability in its Microsoft Office Excel spreadsheet application that could enable a remote code execution attack by hackers. |