Vulnerability Description
Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | 4.4.2 |
Related Weaknesses (CWE)
References
- ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc
- http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/info.c
- http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/info.c?r1=1.260&r2=1.261Patch
- http://marc.info/?l=php-cvs&m=114374620416389&w=2
- http://rhn.redhat.com/errata/RHSA-2006-0276.html
- http://rhn.redhat.com/errata/RHSA-2006-0549.html
- http://secunia.com/advisories/19599Vendor Advisory
- http://secunia.com/advisories/19775Vendor Advisory
- http://secunia.com/advisories/19832Vendor Advisory
- http://secunia.com/advisories/19979Vendor Advisory
- http://secunia.com/advisories/20052Vendor Advisory
- http://secunia.com/advisories/20210Vendor Advisory
- http://secunia.com/advisories/20222Vendor Advisory
- http://secunia.com/advisories/20951Vendor Advisory
- http://secunia.com/advisories/21125Vendor Advisory
FAQ
What is CVE-2006-0996?
CVE-2006-0996 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large numbe...
How severe is CVE-2006-0996?
CVE-2006-0996 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-0996?
Check the references section above for vendor advisories and patch information. Affected products include: Php Php.