PT-2016-3373 · Php+2 · Php+2

Taoguangchen

·

Published

2016-09-11

·

Updated

2018-01-05

·

CVE-2016-7125

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.6.25 PHP versions 7.x prior to 7.0.10
Description The issue exists due to the failure to neutralize special elements in the ext/session/session.c component of the PHP interpreter. This allows a remote attacker to modify user session data by injecting arbitrary-type session data, potentially demonstrated through object injection, by leveraging control of a session name.
Recommendations For PHP versions prior to 5.6.25, update to version 5.6.25 or later. For PHP versions 7.x prior to 7.0.10, update to version 7.0.10 or later.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02403
CVE-2016-7125
DLA-628-1
DSA-3689-1
OPENSUSE-SU-2016_2337-1
OPENSUSE-SU-2016_2451-1
RHSA-2016:2750
SUSE-SU-2016:2328-1
SUSE-SU-2016:2408-1
SUSE-SU-2016:2459-1
SUSE-SU-2016:2460-1
SUSE-SU-2016:2460-2
USN-3095-1

Affected Products

Php
Suse
Ubuntu