Описание
The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.
Релиз | Статус | Примечание |
---|---|---|
dapper | released | 5.1.2-1ubuntu3.19 |
devel | not-affected | 5.3.3-1ubuntu6 |
hardy | released | 5.2.4-2ubuntu5.12 |
jaunty | released | 5.2.6.dfsg.1-3ubuntu4.6 |
karmic | released | 5.2.10.dfsg.1-2ubuntu6.5 |
lucid | released | 5.3.2-1ubuntu4.5 |
upstream | released | 5.3.3, 5.2.14 |
Показывать по
EPSS
5 Medium
CVSS2
Связанные уязвимости
The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.
The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.
The default session serializer in PHP 5.2 through 5.2.13 and 5.3 throu ...
The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.
EPSS
5 Medium
CVSS2