9.3
CVSSv2

CVE-2006-3016

Published: 14/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unspecified vulnerability in session.c in PHP prior to 5.1.3 has unknown impact and attack vectors, related to "certain characters in session names," including special characters that are frequently associated with CRLF injection, SQL injection, cross-site scripting (XSS), and HTTP response splitting vulnerabilities. NOTE: while the nature of the vulnerability is unspecified, it is likely that this is related to a violation of an expectation by PHP applications that the session name is alphanumeric, as implied in the PHP manual for session_name().

Vulnerable Product Search on Vulmon Subscribe to Product

php group php

Vendor Advisories

Debian Bug report logs - #382259 PHP 443 and 444 fix security bugs (CVE-2006-301[67], et al) Package: php4; Maintainer for php4 is (unknown); Reported by: Stefan Fritsch <sf@sfritschde> Date: Wed, 9 Aug 2006 20:03:02 UTC Severity: grave Tags: fixed, fixed-upstream, security, upstream Done: Ondřej Surý <ondrej ...
The phpinfo() PHP function did not properly sanitize long strings A remote attacker could use this to perform cross-site scripting attacks against sites that have publicly-available PHP scripts that call phpinfo() Please note that it is not recommended to publicly expose phpinfo() (CVE-2006-0996) ...