Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-1396
Description:The import_request_variables function in PHP 4.0.7 through 4.4.6, and 5.x before 5.2.2, when called without a prefix, does not prevent the (1) GET, (2) POST, (3) COOKIE, (4) FILES, (5) SERVER, (6) SESSION, and other superglobals from being overwritten, which allows remote attackers to spoof source IP address and Referer data, and have other unspecified impact. NOTE: it could be argued that this is a design limitation of PHP and that only the misuse of this feature, i.e. implementation bugs in applications, should be included in CVE. However, it has been fixed by the vendor.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-1396
BugTraq ID: 22886
http://www.securityfocus.com/bid/22886
Bugtraq: 20070308 PHP import_request_variables() arbitrary variable overwrite (Google Search)
http://www.securityfocus.com/archive/1/462263/100/0/threaded
Bugtraq: 20070310 Re: [Full-disclosure] PHP import_request_variables() arbitrary variable overwrite (Google Search)
http://www.securityfocus.com/archive/1/462457/100/0/threaded
Bugtraq: 20070312 Re: [Full-disclosure] PHP import_request_variables() arbitrary variable overwrite (Google Search)
http://www.securityfocus.com/archive/1/462658/100/0/threaded
Bugtraq: 20070314 Re: Re: [Full-disclosure] PHP import_request_variables() arbitrary variable overwrite (Google Search)
http://www.securityfocus.com/archive/1/462800/100/0/threaded
http://secunia.com/advisories/26048
http://securityreason.com/securityalert/2406
SuSE Security Announcement: SUSE-SA:2007:044 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html




© 1998-2025 E-Soft Inc. All rights reserved.