1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
|
PublicDate: 2006-06-14
Candidate: CVE-2006-3016
References:
http://www.ubuntu.com/usn/usn-320-1
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3016
Description:
Unspecified vulnerability in session.c in PHP before 5.1.3 has unknown
impact and attack vectors, related to "certain characters in session
names," including special characters that are frequently associated with
CRLF injection, SQL injection, cross-site scripting (XSS), and HTTP
response splitting vulnerabilities. NOTE: while the nature of the
vulnerability is unspecified, it is likely that this is related to a
violation of an expectation by PHP applications that the session name is
alphanumeric, as implied in the PHP manual for session_name().
Ubuntu-Description:
Notes:
Bugs:
dapper_php5: released (5.1.2-1ubuntu3.9)
edgy_php5: not-affected
feisty_php5: not-affected
devel_php5: not-affected
upstream_php5:
|