CVE Database
/

CVE-2006-4433

Back to search

CVE-2006-4433

Published: Aug 29, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

PHP before 4.4.3 and 5.x before 5.1.4 does not limit the character set of the session identifier (PHPSESSID) for third party session handlers, which might make it easier for remote attackers to exploit other vulnerabilities by inserting PHP code into the PHPSESSID, which is stored in the session file. NOTE: it could be argued that this not a vulnerability in PHP itself, rather a design limitation that enables certain attacks against session handlers that do not account for this limitation.

VendorProductVersions

n/a

n/a

affected
n/a

References

28233
vdb-entry
x_refsource_OSVDB
1466
third-party-advisory
x_refsource_SREASON
28273
vdb-entry
x_refsource_OSVDB
21573
third-party-advisory
x_refsource_SECUNIA
ADV-2006-3388
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now