Back to search
CVE-2006-0207
Published: Jan 13, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
19355
third-party-advisory
x_refsource_SECUNIA
1015484
vdb-entry
x_refsource_SECTRACK
USN-261-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SR:2006:004
vendor-advisory
x_refsource_SUSE
18431
third-party-advisory
x_refsource_SECUNIA
ADV-2006-0369
vdb-entry
x_refsource_VUPEN
ADV-2006-0177
vdb-entry
x_refsource_VUPEN
19179
third-party-advisory
x_refsource_SECUNIA
http://www.hardened-php.net/advisory_012006.112.html
x_refsource_MISC
GLSA-200603-22
vendor-advisory
x_refsource_GENTOO
DSA-1331
vendor-advisory
x_refsource_DEBIAN
18697
third-party-advisory
x_refsource_SECUNIA
php-session-response-splitting(24094)
vdb-entry
x_refsource_XF
25945
third-party-advisory
x_refsource_SECUNIA
MDKSA-2006:028
vendor-advisory
x_refsource_MANDRIVA
http://www.php.net/release_5_1_2.php
x_refsource_CONFIRM
19012
third-party-advisory
x_refsource_SECUNIA
16220
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now