CVE-2006-4433

N/A Unknown
Published: August 29, 2006 Modified: April 16, 2026
View on NVD

Description

PHP before 4.4.3 and 5.x before 5.1.4 does not limit the character set of the session identifier (PHPSESSID) for third party session handlers, which might make it easier for remote attackers to exploit other vulnerabilities by inserting PHP code into the PHPSESSID, which is stored in the session file. NOTE: it could be argued that this not a vulnerability in PHP itself, rather a design limitation that enables certain attacks against session handlers that do not account for this limitation.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/21573
Source: cve@mitre.org
Patch Vendor Advisory
http://www.hardened-php.net/advisory_052006.128.html
Source: cve@mitre.org
Patch Vendor Advisory
http://www.osvdb.org/28233
Source: cve@mitre.org
http://www.osvdb.org/28273
Source: cve@mitre.org
http://secunia.com/advisories/21573
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://securityreason.com/securityalert/1466
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.hardened-php.net/advisory_052006.128.html
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://www.osvdb.org/28233
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/28273
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/444263/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/3388
Source: af854a3a-2127-422b-91ae-364da2661108

14 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
2.8%
86th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

php