PT-2006-3921 · Php+1 · Php+1

Publicado

2006-06-14

·

Atualizado

2018-10-18

·

CVE-2006-3016

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.1.3
Description The issue is related to certain characters in session names, which could potentially lead to security problems such as CRLF injection, SQL injection, cross-site scripting (XSS), and HTTP response splitting. This might be due to a violation of the expectation that session names are alphanumeric.
Recommendations For PHP versions prior to 5.1.3, update to version 5.1.3 or later to resolve the issue. As a temporary workaround, consider restricting session names to alphanumeric characters to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3016
RHSA-2006:0669
RHSA-2006_0669

Produtos afetados

Php
Red Hat