7.5
CVSSv2

CVE-2006-4433

Published: 29/08/2006 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP prior to 4.4.3 and 5.x prior to 5.1.4 does not limit the character set of the session identifier (PHPSESSID) for third party session handlers, which might make it easier for remote malicious users to exploit other vulnerabilities by inserting PHP code into the PHPSESSID, which is stored in the session file. NOTE: it could be argued that this not a vulnerability in PHP itself, rather a design limitation that enables certain attacks against session handlers that do not account for this limitation.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 4.0.1

php php 4.0.7

php php 4.0

php php 4.2.2

php php 4.2.3

php php 4.3.4

php php 4.3.5

php php 4.4.2

php php 5.0.0

php php 5.0.1

php php 5.0.2

php php 5.1.0

php php 4.0.0

php php 4.0.5

php php 4.0.6

php php 4.2.0

php php 4.2.1

php php 4.3.2

php php 4.3.3

php php 4.4.0

php php 4.4.1

php php 5.0

php php 4.0.2

php php 4.0.3

php php 4.1.0

php php 4.2

php php 4.3.0

php php 4.3.1

php php 4.3.6

php php 4.3.7

php php 5.0.3

php php 5.0.4

php php 5.1.1

php php 5.1.2

php php 4.0.4

php php 4.1.1

php php 4.1.2

php php 4.3.10

php php 4.3.11

php php 4.3.8

php php 4.3.9

php php 5.0.5