Логотип exploitDog
bind:"BDU:2022-02403" OR bind:"CVE-2016-7125"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2022-02403" OR bind:"CVE-2016-7125"

Количество 12

Количество 12

fstec логотип

BDU:2022-02403

почти 9 лет назад

Уязвимость компонента ext/session/session.c интерпретатора языка программирования PHP, позволяющая нарушителю изменять данные сеанса пользователя

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7125

почти 9 лет назад

ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows remote attackers to inject arbitrary-type session data by leveraging control of a session name, as demonstrated by object injection.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2016-7125

почти 9 лет назад

ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows remote attackers to inject arbitrary-type session data by leveraging control of a session name, as demonstrated by object injection.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-7125

почти 9 лет назад

ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows remote attackers to inject arbitrary-type session data by leveraging control of a session name, as demonstrated by object injection.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-7125

почти 9 лет назад

ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-r949-99vg-366c

около 3 лет назад

ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows remote attackers to inject arbitrary-type session data by leveraging control of a session name, as demonstrated by object injection.

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:2459-1

больше 8 лет назад

Security update for php53

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:2328-1

почти 9 лет назад

Security update for php53

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:2451-1

больше 8 лет назад

Security update for php5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:2408-1

больше 8 лет назад

Security update for php5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:2460-2

больше 8 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:2460-1

больше 8 лет назад

Security update for php7

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2022-02403

Уязвимость компонента ext/session/session.c интерпретатора языка программирования PHP, позволяющая нарушителю изменять данные сеанса пользователя

CVSS3: 7.5
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2016-7125

ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows remote attackers to inject arbitrary-type session data by leveraging control of a session name, as demonstrated by object injection.

CVSS3: 7.5
1%
Низкий
почти 9 лет назад
redhat логотип
CVE-2016-7125

ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows remote attackers to inject arbitrary-type session data by leveraging control of a session name, as demonstrated by object injection.

CVSS3: 7.5
1%
Низкий
почти 9 лет назад
nvd логотип
CVE-2016-7125

ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows remote attackers to inject arbitrary-type session data by leveraging control of a session name, as demonstrated by object injection.

CVSS3: 7.5
1%
Низкий
почти 9 лет назад
debian логотип
CVE-2016-7125

ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips ...

CVSS3: 7.5
1%
Низкий
почти 9 лет назад
github логотип
GHSA-r949-99vg-366c

ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows remote attackers to inject arbitrary-type session data by leveraging control of a session name, as demonstrated by object injection.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2016:2459-1

Security update for php53

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2016:2328-1

Security update for php53

почти 9 лет назад
suse-cvrf логотип
openSUSE-SU-2016:2451-1

Security update for php5

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2016:2408-1

Security update for php5

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2016:2460-2

Security update for php7

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2016:2460-1

Security update for php7

больше 8 лет назад

Уязвимостей на страницу