PHP < 4.4.3 / 5.1.4 Multiple Vulnerabilities

high Nessus Plugin ID 22268


The remote web server uses a version of PHP that is affected by multiple flaws.


According to its banner, the version of PHP installed on the remote host is older than 4.4.3 / 5.1.4. Such versions may be affected by several issues, including a buffer overflow, heap corruption, and a flaw by which a variable may survive a call to 'unset()'.


Upgrade to PHP version 4.4.3 / 5.1.4 or later.

See Also

Plugin Details

Severity: High

ID: 22268

File Name: php_4_4_3.nasl

Version: 1.26

Type: remote

Family: CGI abuses

Published: 8/25/2006

Updated: 4/11/2022

Configuration: Enable thorough checks

Risk Information


Risk Factor: Medium

Score: 6


Risk Factor: High

Base Score: 9.3

Temporal Score: 7.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: E:POC/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:php:php

Required KB Items: www/PHP

Exploit Ease: No exploit is required

Patch Publication Date: 8/3/2006

Vulnerability Publication Date: 3/28/2006

Reference Information

CVE: CVE-2006-0996, CVE-2006-1490, CVE-2006-1494, CVE-2006-1608, CVE-2006-1990, CVE-2006-1991, CVE-2006-2563, CVE-2006-2660, CVE-2006-3011, CVE-2006-3016, CVE-2006-3017, CVE-2006-3018, CVE-2006-4433

BID: 17296, 17362, 17439, 17843, 18116, 18645, 49634

CWE: 79