CVE-2006-4432: Code Injection
Directory traversal vulnerability in Zend Platform 2.2.1 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the final component of the PHP session identifier (PHPSESSID). NOTE: in some cases, this issue can be leveraged to perform direct static code injection.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4432?
CVE-2006-4432 is considered a critical vulnerability due to its ability to allow remote attackers to overwrite arbitrary files.
How do I fix CVE-2006-4432?
To fix CVE-2006-4432, upgrade Zend Platform to version 2.2.1 or later.
Which versions of Zend Platform are affected by CVE-2006-4432?
CVE-2006-4432 affects Zend Platform versions 2.2.1 and earlier.
Can CVE-2006-4432 be exploited remotely?
Yes, CVE-2006-4432 can be exploited remotely by attackers through directory traversal techniques.
What types of attacks can be performed using CVE-2006-4432?
Attackers can leverage CVE-2006-4432 to overwrite files or potentially perform direct static code injection.