PHP 5.5.x < 5.5.2 Multiple Vulnerabilities
Medium Nessus Network Monitor Plugin ID 6997
SynopsisThe remote web server uses a version of PHP that is affected by multiple vulnerabilities.
DescriptionPHP versions earlier than 5.5.2 are affected by the following vulnerabilities :
- An error exists related to the 'Sessions' subsystem that can allow an attacker to hijack the session of another user. (CVE-2011-4718 / Bug #60491)
- An error exists related to certificate validation, the 'subjectAltName' field and certificates containing NULL bytes. This error can allow spoofing attacks. (CVE-2013-4248)
SolutionApply the vendor patch or upgrade to PHP version 5.5.2 or later.