Php · Php · CVE-2008-5814
**Name of the Vulnerable Software and Affected Versions**
PHP versions prior to 5.2.7
**Description**
A cross-site scripting (XSS) issue exists, potentially allowing remote attackers to inject arbitrary web script or HTML. The `display errors` setting being enabled is a factor in this issue. Due to a lack of details, the full scope and vectors of the attack are unclear.
**Recommendations**
For PHP versions prior to 5.2.7, consider disabling the `display errors` setting to minimize the risk of exploitation.