PT-2007-6835 · Php+1 · Php+1

Published

2007-11-20

·

Updated

2018-10-15

·

CVE-2007-5899

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.2.5
Description The issue allows remote attackers to obtain potentially sensitive information by reading the requests for a non-local URL. This is demonstrated by a rewritten form containing a local session ID, specifically when the ACTION attribute references a non-local URL in local forms. The output add rewrite var function is involved in this issue.
Recommendations For PHP versions prior to 5.2.5, update to version 5.2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and session IDs in local forms to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5899
DSA-1444-1
HPSBUX02332
RHSA-2008:0505
RHSA-2008:0544
RHSA-2008:0545
RHSA-2008:0546
RHSA-2008:0582
RHSA-2008_0544
RHSA-2008_0545

Affected Products

Php
Red Hat