{"id":1707,"date":"2021-01-23T21:30:44","date_gmt":"2021-01-24T02:30:44","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=1707"},"modified":"2021-01-23T21:30:45","modified_gmt":"2021-01-24T02:30:45","slug":"php-vulnerabilities-and-risks","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/","title":{"rendered":"PHP Vulnerabilities and risks"},"content":{"rendered":"\n<p>PHP is one of the most popular programming languages \u200b\u200bon the web. This is used by more than 76% of indexed websites that use a Back End server side programming language. This means that probably 7 out of 10 websites we visit would be using PHP in some way, and what about this? Well, the greater the number of people, the more cybercriminals attack it and take advantage of PHP vulnerabilities that arise.<\/p>\n\n\n\n<p>Currently, PHP support exists only for versions 7.2 to 7.4. For many, it seems a little relevant data, however, when compared with the current scenario regarding its use on the Internet, we evidence an unfavorable field for security. 60% of the platforms that use PHP do so with a version that is already deprecated by the brand.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">PHP vulnerabilities that were breached and were critical<\/h2>\n\n\n\n<p>Security experts and companies dedicated to this work day by day to minimize these vulnerabilities but, this does not apply with expired versions and even so, having the updated version can be found new vulnerabilities that affect and put everyone&#8217;s cybersecurity at risk users and companies. These would be some of the vulnerabilities that emerged for 2020:<\/p>\n\n\n\n<p><strong><em>\u25b8CVE-2020-7066<\/em><\/strong><\/p>\n\n\n\n<p>The manufacturer has only revealed that the vulnerability is located in the PHP get_headers function, implying that this function truncates the headers upon receiving a null byte. This error can cause the headers to leak confidential information or even contain data entered by a possible attacker, for this is considered a critical severity.<\/p>\n\n\n\n<p><strong><em>\u25b8CVE-2020-7063<\/em><\/strong><\/p>\n\n\n\n<p>Due to the incorrect default permissions for files and folders that are set during the execution of Phar :: buildFromIterator when adding files to a TAR archive, a local user could extract files from the TAR archive and gain access to restricted information. Exploitation of this vulnerability requires that the php.ini option phar.readonly be set to 0.<\/p>\n\n\n\n<p><strong><em>\u25b8CVE-2020-12461<\/em><\/strong><\/p>\n\n\n\n<p>This vulnerability allows a remote threat actor to execute arbitrary SQL queries against the PHP Fusion database. According to the experts of the pentest company, this flaw exists due to improper debugging of the data provided by the user in maincore.php.This failure was considered critical with a score of 8\/10 on the CVSS scale.<br><br>See also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/in-which-fields-are-php-scripts-mainly-used\/\">In which fields are PHP scripts mainly used?<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/php-general-purpose-programming-language\/\">PHP \u2013 general purpose programming language<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>PHP is one of the most popular programming languages \u200b\u200bon the web. This is used by more than 76% of indexed websites that use a Back End server side programming language. This means that probably 7 out of 10 websites we visit would be using PHP in some way, and what about this? Well, the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1708,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36,197],"class_list":["post-1707","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-vulnerabilities"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>PHP Vulnerabilities and risks - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"As we well know, PHP is one of the most popular programming languages \u200b\u200bon the web, which is why if vulnerabilities arise it can be a risk...\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PHP Vulnerabilities and risks - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"As we well know, PHP is one of the most popular programming languages \u200b\u200bon the web, which is why if vulnerabilities arise it can be a risk...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-01-24T02:30:44+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-01-24T02:30:45+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/01\/php.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"837\" \/>\n\t<meta property=\"og:image:height\" content=\"500\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/php-vulnerabilities-and-risks\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/php-vulnerabilities-and-risks\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"PHP Vulnerabilities and risks\",\"datePublished\":\"2021-01-24T02:30:44+00:00\",\"dateModified\":\"2021-01-24T02:30:45+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/php-vulnerabilities-and-risks\\\/\"},\"wordCount\":380,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/php-vulnerabilities-and-risks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/01\\\/php.jpg\",\"keywords\":[\"Cybersecurity\",\"Vulnerabilities\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/php-vulnerabilities-and-risks\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/php-vulnerabilities-and-risks\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/php-vulnerabilities-and-risks\\\/\",\"name\":\"PHP Vulnerabilities and risks - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/php-vulnerabilities-and-risks\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/php-vulnerabilities-and-risks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/01\\\/php.jpg\",\"datePublished\":\"2021-01-24T02:30:44+00:00\",\"dateModified\":\"2021-01-24T02:30:45+00:00\",\"description\":\"As we well know, PHP is one of the most popular programming languages \u200b\u200bon the web, which is why if vulnerabilities arise it can be a risk...\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/php-vulnerabilities-and-risks\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/php-vulnerabilities-and-risks\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/php-vulnerabilities-and-risks\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/01\\\/php.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/01\\\/php.jpg\",\"width\":837,\"height\":500},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/php-vulnerabilities-and-risks\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"PHP Vulnerabilities and risks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"PHP Vulnerabilities and risks - Truxgo Server Blog","description":"As we well know, PHP is one of the most popular programming languages \u200b\u200bon the web, which is why if vulnerabilities arise it can be a risk...","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/","og_locale":"es_MX","og_type":"article","og_title":"PHP Vulnerabilities and risks - Truxgo Server Blog","og_description":"As we well know, PHP is one of the most popular programming languages \u200b\u200bon the web, which is why if vulnerabilities arise it can be a risk...","og_url":"https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-01-24T02:30:44+00:00","article_modified_time":"2021-01-24T02:30:45+00:00","og_image":[{"width":837,"height":500,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/01\/php.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"PHP Vulnerabilities and risks","datePublished":"2021-01-24T02:30:44+00:00","dateModified":"2021-01-24T02:30:45+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/"},"wordCount":380,"commentCount":1,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/01\/php.jpg","keywords":["Cybersecurity","Vulnerabilities"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/","url":"https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/","name":"PHP Vulnerabilities and risks - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/01\/php.jpg","datePublished":"2021-01-24T02:30:44+00:00","dateModified":"2021-01-24T02:30:45+00:00","description":"As we well know, PHP is one of the most popular programming languages \u200b\u200bon the web, which is why if vulnerabilities arise it can be a risk...","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/01\/php.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/01\/php.jpg","width":837,"height":500},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"PHP Vulnerabilities and risks"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/1707","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=1707"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/1707\/revisions"}],"predecessor-version":[{"id":1712,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/1707\/revisions\/1712"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/1708"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=1707"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=1707"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=1707"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}