7.5
CVSSv2

CVE-2006-3018

Published: 14/06/2006 Updated: 15/09/2010
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unspecified vulnerability in the session extension functionality in PHP prior to 5.1.3 has unknown impact and attack vectors related to heap corruption.

Vulnerable Product Search on Vulmon Subscribe to Product

php group php

Vendor Advisories

The phpinfo() PHP function did not properly sanitize long strings A remote attacker could use this to perform cross-site scripting attacks against sites that have publicly-available PHP scripts that call phpinfo() Please note that it is not recommended to publicly expose phpinfo() (CVE-2006-0996) ...