6.8 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
0.029 Low
EPSS
Percentile
90.8%
PHP versions earlier than 5.5.2 are affected by the following vulnerabilities :
An error exists related to the ‘Sessions’ subsystem that can allow an attacker to hijack the session of another user. (CVE-2011-4718 / Bug #60491)
An error exists related to certificate validation, the ‘subjectAltName’ field and certificates containing NULL bytes. This error can allow spoofing attacks. (CVE-2013-4248)
Binary data 6997.prm