Advisories Blog | G5 Cyber Security

Hardened-PHP Project Security Advisory 2006-01.112

Hardened-PHP Project Security Advisory – Since PHP5 a user supplied session ID is sent back to the user within a Set-Cookie HTTP header. Because there were no checks performed on the validity of this session id, it was possible to inject arbitrary HTTP headers into the response body of applications using PHP’s builtin session functionality by supplying a special crafted session id. Versions 5.1.1 and below are affected. PHP4 is not affected.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/43068/advisory_012006.112.txt

Source: https://packetstormsecurity.com/files/43068/Hardened-PHP-Project-Security-Advisory-2006-01.112.html

Exit mobile version