2.6
CVSSv2

CVE-2008-5814

Published: 02/01/2009 Updated: 30/10/2018
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in PHP, possibly 5.2.7 and previous versions, when display_errors is enabled, allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors. NOTE: because of the lack of details, it is unclear whether this is related to CVE-2006-0208.

Vulnerable Product Search on Vulmon Subscribe to Product

php php

php php 5.1.1

php php 5.1.0

php php 5.0.5

php php 5.0.0

php php 5

php php 4.4.9

php php 4.4.0

php php 4.4.1

php php 4.3.4

php php 4.3.0

php php 4.1.0

php php 4.2.1

php php 4.0

php php 4.1.1

php php 4.0.6

php php 4.0.7

php php 4.0.1

php php 3.0.4

php php 3.0.3

php php 3.0.11

php php 3.0.10

php php 5.2.4

php php 5.2.3

php php 5.1.4

php php 5.1.5

php php 5.0

php php 4.4.6

php php 4.4.7

php php 4.3.10

php php 4.3.1

php php 4.3.5

php php 4.3.7

php php 4.2

php php 4.2.2

php php 4.0.4

php php 4.0.3

php php 4

php php 3.0.5

php php 3.0.6

php php 3.0.17

php php 3.0.16

php php 2.0b10

php php 2.0

php php 5.2.6

php php 5.2.5

php php 5.1.6

php php 5.2.0

php php 5.0.4

php php 5.0.3

php php 4.4.5

php php 4.4.2

php php 4.4.3

php php 4.4.4

php php 4.3.3

php php 4.3.6

php php 4.2.3

php php 4.0.5

php php 3.0.9

php php 4.0.0

php php 3.0.15

php php 3.0.14

php php 3.0.1

php php 3.0

php php 5.1.3

php php 5.1.2

php php 5.2.1

php php 5.2.2

php php 5.0.2

php php 5.0.1

php php 4.4.8

php php 4.3.8

php php 4.3.9

php php 4.3.2

php php 4.3.11

php php 4.1.2

php php 4.2.0

php php 3.0.7

php php 3.0.8

php php 4.0.2

php php 3.0.2

php php 3.0.18

php php 3.0.13

php php 3.0.12

php php 1.0

Vendor Advisories

Synopsis Moderate: php security update Type/Severity Security Advisory: Moderate Topic Updated php packages that fix several security issues are now available forRed Hat Enterprise Linux 5This update has been rated as having moderate security impact by the RedHat Security Response Team Descriptio ...
Debian Bug report logs - #523028 CVE-2008-5814: XSS vulnerability in PHP <= 527 Package: php5; Maintainer for php5 is Debian PHP Maintainers <pkg-php-maint@listsaliothdebianorg>; Source for php5 is src:php5 (PTS, buildd, popcon) Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: Tue, 7 Apr ...
Debian Bug report logs - #523049 CVE-2009-0754: mbstringfunc_overload setting leakage across vhosts Package: php5; Maintainer for php5 is Debian PHP Maintainers <pkg-php-maint@listsaliothdebianorg>; Source for php5 is src:php5 (PTS, buildd, popcon) Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> D ...
It was discovered that PHP did not sanitize certain error messages when display_errors is enabled, which could result in browsers becoming vulnerable to cross-site scripting attacks when processing the output With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attac ...
USN-761-1 fixed vulnerabilities in PHP This update provides the corresponding updates for Ubuntu 904 ...
Several remote vulnerabilities have been discovered in the PHP 5 hypertext preprocessor The Common Vulnerabilities and Exposures project identifies the following problems The following four vulnerabilities have already been fixed in the stable (lenny) version of php5 prior to the release of lenny This update now addresses them for etch (oldstab ...