PT-2006-6567 · Zend · Zend Framework

Published

2006-11-15

·

Updated

2018-10-17

·

CVE-2006-5900

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Zend Framework Preview version 0.2.0
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via arbitrary parameters in the incubator/tests/Zend/Http/ files/testRedirections.php sample code.
Recommendations For Zend Framework Preview version 0.2.0, consider restricting access to the testRedirections.php sample code until a fix is available. As a temporary workaround, avoid using arbitrary parameters in the affected sample code to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-5900

Affected Products

Zend Framework