CVE-2006-4432

Directory traversal vulnerability in Zend Platform 2.2.1 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the final component of the PHP session identifier (PHPSESSID). NOTE: in some cases, this issue can be leveraged to perform direct static code injection.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:zend:zend_platform:*:a:*:*:*:*:*:*

Information

Published : 2006-08-28 17:04

Updated : 2018-10-17 14:37


NVD link : CVE-2006-4432

Mitre link : CVE-2006-4432


JSON object : View

Advertisement

dedicated server usa

Products Affected

zend

  • zend_platform