CVE-2006-0996: XSS
Published Apr 10, 2006
·Updated
Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.
Affected Software
2 affected components
PHP PHP=5.1.2
PHP PHP=4.4.2
Remediation
Event History
Apr 10, 2006
CVE Published
06:06 PM
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0996?
CVE-2006-0996 has a medium severity rating due to its potential for Cross-site scripting (XSS) attacks.
2
How do I fix CVE-2006-0996?
To fix CVE-2006-0996, upgrade PHP to version 5.1.3 or later, or to version 4.4.3 or later.
3
What versions of PHP are affected by CVE-2006-0996?
CVE-2006-0996 affects PHP versions 5.1.2 and 4.4.2.
4
What type of attack can CVE-2006-0996 enable?
CVE-2006-0996 can enable remote attackers to conduct Cross-site scripting (XSS) attacks.
5
Can CVE-2006-0996 affect web applications?
Yes, CVE-2006-0996 can affect web applications that use the vulnerable PHP versions, allowing for the injection of arbitrary scripts.