Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2006-4433

Опубликовано: 29 авг. 2006
Источник: ubuntu
Приоритет: negligible
CVSS2: 7.5

Описание

PHP before 4.4.3 and 5.x before 5.1.4 does not limit the character set of the session identifier (PHPSESSID) for third party session handlers, which might make it easier for remote attackers to exploit other vulnerabilities by inserting PHP code into the PHPSESSID, which is stored in the session file. NOTE: it could be argued that this not a vulnerability in PHP itself, rather a design limitation that enables certain attacks against session handlers that do not account for this limitation.

РелизСтатусПримечание
dapper

ignored

devel

not-affected

edgy

released

5.1.6-1ubuntu2.6
feisty

released

5.2.1-0ubuntu1.4
gutsy

not-affected

upstream

needs-triage

Показывать по

Ссылки на источники

7.5 High

CVSS2

Связанные уязвимости

nvd
почти 19 лет назад

PHP before 4.4.3 and 5.x before 5.1.4 does not limit the character set of the session identifier (PHPSESSID) for third party session handlers, which might make it easier for remote attackers to exploit other vulnerabilities by inserting PHP code into the PHPSESSID, which is stored in the session file. NOTE: it could be argued that this not a vulnerability in PHP itself, rather a design limitation that enables certain attacks against session handlers that do not account for this limitation.

debian
почти 19 лет назад

PHP before 4.4.3 and 5.x before 5.1.4 does not limit the character set ...

github
больше 3 лет назад

PHP before 4.4.3 and 5.x before 5.1.4 does not limit the character set of the session identifier (PHPSESSID) for third party session handlers, which might make it easier for remote attackers to exploit other vulnerabilities by inserting PHP code into the PHPSESSID, which is stored in the session file. NOTE: it could be argued that this not a vulnerability in PHP itself, rather a design limitation that enables certain attacks against session handlers that do not account for this limitation.

7.5 High

CVSS2