Back

MEDIUM

php: htmlspecialchars() insufficient checking of input for multi-byte encodings

Published Dec 21, 2009

Description

The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 21, 2009
Updated Aug 7, 2024
Reserved Dec 1, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Oct 6, 2009