|
|
| |
|
| |
php5: header injection
| Package(s): | php5 |
CVE #(s): | CVE-2012-4388
|
| Created: | September 17, 2012 |
Updated: | September 19, 2012 |
| Description: |
From the CVE entry:
The sapi_header_op function in main/SAPI.c in PHP 5.4.0RC2 through 5.4.0 does not properly determine a pointer during checks for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1398.
|
| Alerts: |
|
( Log in to post comments)
|
|
|