Количество 10
Количество 10

CVE-2016-5385
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue.

CVE-2016-5385
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue.

CVE-2016-5385
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue.
CVE-2016-5385
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 ...
ELSA-2016-1613
ELSA-2016-1613: php security and bug fix update (MODERATE)
ELSA-2016-1609
ELSA-2016-1609: php security update (MODERATE)

openSUSE-SU-2016:3092-1
Security update for php7

SUSE-SU-2016:2941-1
Security update for php7

openSUSE-SU-2016:1922-1
Security update for php5

SUSE-SU-2016:1842-1
Security update for php5
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2016-5385 PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. | CVSS3: 8.1 | 80% Высокий | почти 9 лет назад |
![]() | CVE-2016-5385 PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. | CVSS3: 5 | 80% Высокий | почти 9 лет назад |
![]() | CVE-2016-5385 PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. | CVSS3: 8.1 | 80% Высокий | почти 9 лет назад |
CVE-2016-5385 PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 ... | CVSS3: 8.1 | 80% Высокий | почти 9 лет назад | |
ELSA-2016-1613 ELSA-2016-1613: php security and bug fix update (MODERATE) | почти 9 лет назад | |||
ELSA-2016-1609 ELSA-2016-1609: php security update (MODERATE) | почти 9 лет назад | |||
![]() | openSUSE-SU-2016:3092-1 Security update for php7 | больше 8 лет назад | ||
![]() | SUSE-SU-2016:2941-1 Security update for php7 | больше 8 лет назад | ||
![]() | openSUSE-SU-2016:1922-1 Security update for php5 | почти 9 лет назад | ||
![]() | SUSE-SU-2016:1842-1 Security update for php5 | почти 9 лет назад |
Уязвимостей на страницу