Lucene search

K
cveMitreCVE-2006-0207
HistoryJan 13, 2006 - 11:03 p.m.

CVE-2006-0207

2006-01-1323:03:00
CWE-94
mitre
web.nvd.nist.gov
55
cve
php
http response splitting
vulnerability
remote code injection
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.6

Confidence

Low

EPSS

0.013

Percentile

85.9%

Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.

Affected configurations

Nvd
Node
phpphpMatch5.0rc1
OR
phpphpMatch5.0rc2
OR
phpphpMatch5.0rc3
OR
phpphpMatch5.0.0
OR
phpphpMatch5.0.1
OR
phpphpMatch5.0.2
OR
phpphpMatch5.0.3
OR
phpphpMatch5.0.4
OR
phpphpMatch5.0.5
OR
phpphpMatch5.1.0
OR
phpphpMatch5.1.1
VendorProductVersionCPE
phpphp5.1.1cpe:/a:php:php:5.1.1:::
phpphp5.0cpe:/a:php:php:5.0:rc1::
phpphp5.0.4cpe:/a:php:php:5.0.4:::
phpphp5.0.0cpe:/a:php:php:5.0.0:::
phpphp5.0.2cpe:/a:php:php:5.0.2:::
phpphp5.0cpe:/a:php:php:5.0:rc2::
phpphp5.0.5cpe:/a:php:php:5.0.5:::
phpphp5.0cpe:/a:php:php:5.0:rc3::
phpphp5.0.3cpe:/a:php:php:5.0.3:::
phpphp5.1.0cpe:/a:php:php:5.1.0:::
Rows per page:
1-10 of 111

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.6

Confidence

Low

EPSS

0.013

Percentile

85.9%