Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

PHP EXT/Session HTTP Response Header Injection Vulnerability

To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.

The following proof of concept is available:

http://www.example.com/session.php/PHPSESSID=ID;INJECTED=ATTRIBUTE;/







 

Privacy Statement
Copyright 2008, SecurityFocus