|
PHP EXT/Session HTTP Response Header Injection Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI. The following proof of concept is available: http://www.example.com/session.php/PHPSESSID=ID;INJECTED=ATTRIBUTE;/ |
|
|
Privacy Statement |