First published: Mon Feb 01 2016(Updated: )
examples/consumer/common.php in JanRain PHP OpenID library (aka php-openid) improperly checks the openid.realm parameter against the SERVER_NAME element in the SERVER superglobal array, which might allow remote attackers to hijack the authentication of arbitrary users via vectors involving a crafted HTTP Host header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Janrain Php-openid |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.