Out-of-date Version (phpList)
Summary#
Invicti identified the target web site is using phpList and detected that it is out of date. phpList is an open source e-mail marketing system.
Impact#
Since this is an old version of the software, it may be vulnerable to attacks.
Remediation#
Please upgrade your installation of phpList to the latest stable version.
Classifications#
Invicti Security Insights
- Sven Morgenroth Talks About PHP Object Injection Vulnerabilities on Paul’s Security Weekly Podcast
- End of Support for PHP 5 and PHP 7.0
- PHP Wrappers, Streams & Local File Intrusion (LFI)
- Sven Morgenroth Talks About PHP Type Juggling on Paul’s Security Weekly Podcast
- PHP Type Juggling Exploit: Vulnerability, Payloads, and Fixes