Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2007-1287
StatusCandidate
DescriptionA regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP 6.0 in CVS, allows remote attackers to conduct cross-site scripting (XSS) attacks via GET, POST, or COOKIE array values, which are not escaped in the phpinfo output, as originally fixed for CVE-2005-3388.
SeverityLow
CVSS score1,9
CVSS vector(AV:R/AC:H/Au:NR/C:N/I:P/A:N/B:N)
PhaseAssigned (06.03.2007)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1287
ReferencesCONFIRM : http://us2.php.net/releases/4_4_7.php
 MISC : http://www.php-security.org/MOPB/MOPB-08-2007.html
 OSVDB : 32774
SecurityVulns:Multiple PHP bugs

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server