Back

MEDIUM

php session ID leakage

Published Nov 20, 2007

Description

The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (34)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 20, 2007
Updated Aug 7, 2024
Reserved Nov 8, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Nov 8, 2007