PT-2006-3921 · Php+1 · Php+1

Published

2006-06-14

·

Updated

2018-10-18

·

CVE-2006-3016

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.1.3
Description The issue is related to certain characters in session names, which could potentially lead to security problems such as CRLF injection, SQL injection, cross-site scripting (XSS), and HTTP response splitting. This might be due to a violation of the expectation that session names are alphanumeric.
Recommendations For PHP versions prior to 5.1.3, update to version 5.1.3 or later to resolve the issue. As a temporary workaround, consider restricting session names to alphanumeric characters to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3016
RHSA-2006:0669
RHSA-2006_0669

Affected Products

Php
Red Hat