Back to search
CVE-2006-0208
Published: Jan 13, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
19355
third-party-advisory
x_refsource_SECUNIA
21252
third-party-advisory
x_refsource_SECUNIA
USN-261-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SR:2006:004
vendor-advisory
x_refsource_SUSE
18431
third-party-advisory
x_refsource_SECUNIA
20222
third-party-advisory
x_refsource_SECUNIA
20210
third-party-advisory
x_refsource_SECUNIA
ADV-2006-0369
vdb-entry
x_refsource_VUPEN
http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm
x_refsource_CONFIRM
ADV-2006-0177
vdb-entry
x_refsource_VUPEN
RHSA-2006:0276
vendor-advisory
x_refsource_REDHAT
19179
third-party-advisory
x_refsource_SECUNIA
GLSA-200603-22
vendor-advisory
x_refsource_GENTOO
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=178028
x_refsource_MISC
RHSA-2006:0501
vendor-advisory
x_refsource_REDHAT
RHSA-2006:0549
vendor-advisory
x_refsource_REDHAT
18697
third-party-advisory
x_refsource_SECUNIA
20951
third-party-advisory
x_refsource_SECUNIA
http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm
x_refsource_CONFIRM
19832
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:10064
vdb-entry
signature
x_refsource_OVAL
MDKSA-2006:028
vendor-advisory
x_refsource_MANDRIVA
http://www.php.net/release_5_1_2.php
x_refsource_CONFIRM
16803
vdb-entry
x_refsource_BID
21564
third-party-advisory
x_refsource_SECUNIA
19012
third-party-advisory
x_refsource_SECUNIA
http://www.php.net/ChangeLog-4.php#4.4.2
x_refsource_CONFIRM
ADV-2006-2685
vdb-entry
x_refsource_VUPEN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now