Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2006-4433

Опубликовано: 29 авг. 2006
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS2: 7.5

Описание

PHP before 4.4.3 and 5.x before 5.1.4 does not limit the character set of the session identifier (PHPSESSID) for third party session handlers, which might make it easier for remote attackers to exploit other vulnerabilities by inserting PHP code into the PHPSESSID, which is stored in the session file. NOTE: it could be argued that this not a vulnerability in PHP itself, rather a design limitation that enables certain attacks against session handlers that do not account for this limitation.

РелизСтатусПримечание
dapper

ignored

devel

not-affected

edgy

released

5.1.6-1ubuntu2.6
feisty

released

5.2.1-0ubuntu1.4
gutsy

not-affected

upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 85%
0.02722
Низкий

7.5 High

CVSS2

Связанные уязвимости

nvd
почти 19 лет назад

PHP before 4.4.3 and 5.x before 5.1.4 does not limit the character set of the session identifier (PHPSESSID) for third party session handlers, which might make it easier for remote attackers to exploit other vulnerabilities by inserting PHP code into the PHPSESSID, which is stored in the session file. NOTE: it could be argued that this not a vulnerability in PHP itself, rather a design limitation that enables certain attacks against session handlers that do not account for this limitation.

debian
почти 19 лет назад

PHP before 4.4.3 and 5.x before 5.1.4 does not limit the character set ...

github
около 3 лет назад

PHP before 4.4.3 and 5.x before 5.1.4 does not limit the character set of the session identifier (PHPSESSID) for third party session handlers, which might make it easier for remote attackers to exploit other vulnerabilities by inserting PHP code into the PHPSESSID, which is stored in the session file. NOTE: it could be argued that this not a vulnerability in PHP itself, rather a design limitation that enables certain attacks against session handlers that do not account for this limitation.

EPSS

Процентиль: 85%
0.02722
Низкий

7.5 High

CVSS2