|
|
| |
|
| |
php: header injection
| Package(s): | PHP5 |
CVE #(s): | CVE-2011-1398
CVE-2011-4388
|
| Created: | September 13, 2012 |
Updated: | February 28, 2013 |
| Description: |
From the Ubuntu advisory:
It was discovered that PHP incorrectly handled certain character sequences
when applying HTTP response-splitting protection. A remote attacker could
create a specially-crafted URL and inject arbitrary headers.
(CVE-2011-1398, CVE-2012-4388) |
| Alerts: |
|
( Log in to post comments)
|
|
|