Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-3016

EPSS 6.74% · P91
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-3016

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Unspecified vulnerability in session.c in PHP before 5.1.3 has unknown impact and attack vectors, related to "certain characters in session names," including special characters that are frequently associated with CRLF injection, SQL injection, cross-site scripting (XSS), and HTTP response splitting vulnerabilities. NOTE: while the nature of the vulnerability is unspecified, it is likely that this is related to a violation of an expectation by PHP applications that the session name is alphanumeric, as implied in the PHP manual for session_name().
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
PHP session.c 未明漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
PHP是广泛使用的通用目的脚本语言,特别适合于Web开发,可嵌入到HTML中。 PHP 5.1.3 之前的版本中的 session.c 存在未明漏洞,具有未知影响和未知向量,与 "会话中的特点字符"有关,包括常常与CRLF注入,SQL注入,跨站点脚本攻击(XSS)和HTTP响应拆分漏洞相关联的特殊字符。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-3016

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-3016

登录查看更多情报信息。

Same Patch Batch · n/a · 2006-06-14 · 8 CVEs total

CVE-2006-3017PHP zend_hash.c 输入验证漏洞
CVE-2006-3018PHP 会话扩展功能 未明漏洞
CVE-2002-2214PHP IMAP 服务拒绝漏洞
CVE-2002-2215PHP imap_header服务拒绝漏洞
CVE-2003-1302PHP服务拒绝漏洞
CVE-2003-1303PHP缓冲区溢出漏洞
CVE-2006-3015WinSCP 多个自变量注入漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2006-3016

No comments yet


Leave a comment