PT-2009-1301 · Php+1 · Php+1

Tomoki Sanaki

·

Published

2009-01-02

·

Updated

2018-10-30

·

CVE-2008-5814

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.2.7
Description A cross-site scripting (XSS) issue exists, potentially allowing remote attackers to inject arbitrary web script or HTML. The display errors setting being enabled is a factor in this issue. Due to a lack of details, the full scope and vectors of the attack are unclear.
Recommendations For PHP versions prior to 5.2.7, consider disabling the display errors setting to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-5814
DSA-1789-1
RHSA-2009:0338
RHSA-2009:0350
RHSA-2009_0338

Affected Products

Php
Red Hat