PT-2010-4522 · Php+1 · Php+1

Publicado

2010-08-20

·

Atualizado

2010-12-10

·

CVE-2010-3065

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP versions 5.2 through 5.2.13 PHP versions 5.3 through 5.3.2
Description The issue arises from the default session serializer in PHP not properly handling the PS UNDEF MARKER marker. This allows attackers to modify arbitrary session variables by using a crafted session variable name.
Recommendations For PHP versions 5.2 through 5.2.13, update to a version outside of this range to resolve the issue. For PHP versions 5.3 through 5.3.2, update to a version outside of this range to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-3065
DSA-2089-1
RHSA-2010:0919
RHSA-2010_0919

Produtos afetados

Php
Red Hat