Unspecified vulnerability in the session extension functionality in PHP before 5.1.3 has unknown impact and attack vectors related to heap corruption.
http://secunia.com/advisories/19927
http://secunia.com/advisories/21050
http://secunia.com/advisories/21125
http://securitytracker.com/id?1016306
http://www.mandriva.com/security/advisories?name=MDKSA-2006:122
http://www.php.net/release_5_1_3.php
Source: MITRE
Published: 2006-06-14
Updated: 2010-09-15
Type: NVD-CWE-Other
Base Score: 7.5
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 10
Severity: HIGH
OR
cpe:2.3:a:php_group:php:*:*:*:*:*:*:*:* versions up to 5.1.2 (inclusive)
ID | Name | Product | Family | Severity |
---|---|---|---|---|
27897 | Ubuntu 5.04 / 5.10 / 6.06 LTS : php4, php5 vulnerabilities (USN-320-1) | Nessus | Ubuntu Local Security Checks | high |
3509 | PHP 5.1.x < 5.1.4 Multiple Vulnerabilities | Nessus Network Monitor | Web Servers | medium |
22268 | PHP < 4.4.3 / 5.1.4 Multiple Vulnerabilities | Nessus | CGI abuses | high |
22053 | Mandrake Linux Security Advisory : php (MDKSA-2006:122) | Nessus | Mandriva Local Security Checks | critical |
801115 | PHP < 5.1.4 Multiple Vulnerabilities | Log Correlation Engine | Web Servers | high |
801113 | PHP < 5.0.6 GLOBAL Variable Overwrite | Log Correlation Engine | Web Servers | high |