PT-2007-6835 · Php+1 · Php+1

Publicado

2007-11-20

·

Atualizado

2018-10-15

·

CVE-2007-5899

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.2.5
Description The issue allows remote attackers to obtain potentially sensitive information by reading the requests for a non-local URL. This is demonstrated by a rewritten form containing a local session ID, specifically when the ACTION attribute references a non-local URL in local forms. The output add rewrite var function is involved in this issue.
Recommendations For PHP versions prior to 5.2.5, update to version 5.2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and session IDs in local forms to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5899
DSA-1444-1
HPSBUX02332
RHSA-2008:0505
RHSA-2008:0544
RHSA-2008:0545
RHSA-2008:0546
RHSA-2008:0582
RHSA-2008_0544
RHSA-2008_0545

Produtos afetados

Php
Red Hat