CVE-2006-0887
Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib distribution is available on the server, allows remote attackers to execute arbitrary PHP code by including a base64-encoded…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.45%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib distribution is available on the server, allows remote attackers to execute arbitrary PHP code by including a base64-encoded representation of the code in a cookie. NOTE: this description was significantly updated on 20060605 to reflect new details after an initial vague advisory.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 3.45% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- phplib team/phplib
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/16902Patch, Vendor Advisory
- http://securitytracker.com/id?1016123
- http://sourceforge.net/project/shownotes.php?group_id=31885&release_id=396091Patch
- http://www.gulftech.org/?node=research&article_id=00107-03052006
- http://www.osvdb.org/23466
- http://www.securityfocus.com/bid/16801
- http://www.vupen.com/english/advisories/2006/0720Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24873
- http://secunia.com/advisories/16902Patch, Vendor Advisory
- http://securitytracker.com/id?1016123
- http://sourceforge.net/project/shownotes.php?group_id=31885&release_id=396091Patch
- http://www.gulftech.org/?node=research&article_id=00107-03052006
- http://www.osvdb.org/23466
- http://www.securityfocus.com/bid/16801
- http://www.vupen.com/english/advisories/2006/0720Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24873
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.