Описание
The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID.
Релиз | Статус | Примечание |
---|---|---|
dapper | released | 5.1.2-1ubuntu3.10 |
devel | not-affected | 5.2.6-1ubuntu1 |
edgy | released | 5.1.6-1ubuntu2.7 |
feisty | released | 5.2.1-0ubuntu1.5 |
gutsy | released | 5.2.3-1ubuntu6.1 |
hardy | released | 5.2.4-2ubuntu5.3 |
upstream | released | 5.2.5 |
Показывать по
4.3 Medium
CVSS2
Связанные уязвимости
The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID.
The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID.
The output_add_rewrite_var function in PHP before 5.2.5 rewrites local ...
The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID.
4.3 Medium
CVSS2