Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.
References
Link Resource
ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc
http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html
http://rhn.redhat.com/errata/RHSA-2006-0276.html
http://rhn.redhat.com/errata/RHSA-2006-0549.html Vendor Advisory
http://secunia.com/advisories/18431 Patch Vendor Advisory
http://secunia.com/advisories/18697 Patch Vendor Advisory
http://secunia.com/advisories/19012 Vendor Advisory
http://secunia.com/advisories/19179 Patch Vendor Advisory
http://secunia.com/advisories/19355 Patch Vendor Advisory
http://secunia.com/advisories/19832 Vendor Advisory
http://secunia.com/advisories/20210 Vendor Advisory
http://secunia.com/advisories/20222 Vendor Advisory
http://secunia.com/advisories/20951 Vendor Advisory
http://secunia.com/advisories/21252 Vendor Advisory
http://secunia.com/advisories/21564 Vendor Advisory
http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm
http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm
http://www.gentoo.org/security/en/glsa/glsa-200603-22.xml Patch Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2006:028
http://www.php.net/ChangeLog-4.php#4.4.2
http://www.php.net/release_5_1_2.php Patch
http://www.redhat.com/support/errata/RHSA-2006-0501.html Vendor Advisory
http://www.securityfocus.com/bid/16803 Patch
http://www.vupen.com/english/advisories/2006/0177 Vendor Advisory
http://www.vupen.com/english/advisories/2006/0369 Vendor Advisory
http://www.vupen.com/english/advisories/2006/2685 Vendor Advisory
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=178028
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10064
https://usn.ubuntu.com/261-1/
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2006-01-13T23:00:00

Updated: 2018-10-03T20:57:01

Reserved: 2006-01-13T00:00:00


Link: CVE-2006-0208

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2006-01-13T23:03:00.000

Modified: 2018-10-30T16:25:35.387


Link: CVE-2006-0208

JSON object: View

cve-icon Redhat Information

No data.

CWE