PHP Import_Request_Variables Arbitrary Variable Overwrite Vulnerability
BID:22886
Info
PHP Import_Request_Variables Arbitrary Variable Overwrite Vulnerability
| Bugtraq ID: | 22886 |
| Class: | Design Error |
| CVE: |
CVE-2007-1396 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 09 2007 12:00AM |
| Updated: | Mar 19 2015 08:45AM |
| Credit: | Stefano Di Paola and Stefan Esser independently discovered this vulnerability. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10.SP1 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Novell Linux POS 9 S.u.S.E. Linux Openexchange Server S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc PHP-Nuke PHP-Nuke 8.0 PHP PHP 5.2.1 PHP PHP 5.1.6 PHP PHP 5.1.5 PHP PHP 5.1.4 PHP PHP 5.1.3 -RC1 PHP PHP 5.1.3 PHP PHP 5.1.2 PHP PHP 5.1.1 PHP PHP 5.1 PHP PHP 5.0.5 PHP PHP 5.0.4 PHP PHP 5.0.3 PHP PHP 5.0.2 PHP PHP 5.0.1 PHP PHP 5.0 candidate 3 PHP PHP 5.0 candidate 2 PHP PHP 5.0 candidate 1 PHP PHP 5.0 .0 PHP PHP 4.4.6 PHP PHP 4.4.5 PHP PHP 4.4.4 PHP PHP 4.4.3 PHP PHP 4.4.2 PHP PHP 4.4.1 PHP PHP 4.4 .0 PHP PHP 4.3.11 PHP PHP 4.3.10 PHP PHP 4.3.9 PHP PHP 4.3.8 PHP PHP 4.3.7 PHP PHP 4.3.6 PHP PHP 4.3.5 PHP PHP 4.3.4 PHP PHP 4.3.3 PHP PHP 4.3.2 PHP PHP 4.3.1 PHP PHP 4.3 PHP PHP 4.2.3 PHP PHP 4.2.2 PHP PHP 4.2.1 PHP PHP 4.2 .0 PHP PHP 4.2 -dev PHP PHP 4.1.2 PHP PHP 4.1.1 PHP PHP 4.1 .0 PHP PHP 4.0.7 RC3 PHP PHP 4.0.7 RC2 PHP PHP 4.0.7 RC1 PHP PHP 4.0.7 PHP PHP 5.2 |
| Not Vulnerable: |
PHP PHP 5.2.2 PHP PHP 4.4.7 |
Discussion
PHP Import_Request_Variables Arbitrary Variable Overwrite Vulnerability
PHP is prone to a vulnerability that permits an attacker to overwrite arbitrary variables due to a design error.
Successful exploits will allow remote attackers to overwrite arbitrary variables. This may result in a complete compromise of vulnerable applications or denial-of-service conditions.
PHP versions from 4.0.7 to 5.2.1 are vulnerable to this issue.
PHP is prone to a vulnerability that permits an attacker to overwrite arbitrary variables due to a design error.
Successful exploits will allow remote attackers to overwrite arbitrary variables. This may result in a complete compromise of vulnerable applications or denial-of-service conditions.
PHP versions from 4.0.7 to 5.2.1 are vulnerable to this issue.
Exploit / POC
PHP Import_Request_Variables Arbitrary Variable Overwrite Vulnerability
Attackers may exploit this issue via a web browser.
The following proof-of-concept is available:
Attackers may exploit this issue via a web browser.
The following proof-of-concept is available:
Solution / Fix
PHP Import_Request_Variables Arbitrary Variable Overwrite Vulnerability
Solution:
The vendor has addressed this issue in the latest CVS repository. Contact the vendor for details on obtaining and applying the appropriate updates.
PHP PHP 5.2
PHP PHP 4.0.7
PHP PHP 4.0.7 RC1
PHP PHP 4.0.7 RC3
PHP PHP 4.0.7 RC2
PHP PHP 4.1 .0
PHP PHP 4.1.1
PHP PHP 4.1.2
PHP PHP 4.2 -dev
PHP PHP 4.2 .0
PHP PHP 4.2.1
PHP PHP 4.2.2
PHP PHP 4.2.3
PHP PHP 4.3
PHP PHP 4.3.1
PHP PHP 4.3.10
PHP PHP 4.3.11
PHP PHP 4.3.2
PHP PHP 4.3.3
PHP PHP 4.3.4
PHP PHP 4.3.5
PHP PHP 4.3.6
PHP PHP 4.3.7
PHP PHP 4.3.8
PHP PHP 4.3.9
PHP PHP 4.4 .0
PHP PHP 4.4.1
PHP PHP 4.4.2
PHP PHP 4.4.3
PHP PHP 4.4.4
PHP PHP 4.4.5
PHP PHP 4.4.6
PHP PHP 5.0 .0
PHP PHP 5.0 candidate 2
PHP PHP 5.0 candidate 3
PHP PHP 5.0 candidate 1
PHP PHP 5.0.1
PHP PHP 5.0.2
PHP PHP 5.0.3
PHP PHP 5.0.4
PHP PHP 5.0.5
PHP PHP 5.1
PHP PHP 5.1.1
PHP PHP 5.1.2
PHP PHP 5.1.3 -RC1
PHP PHP 5.1.3
PHP PHP 5.1.4
PHP PHP 5.1.5
PHP PHP 5.1.6
PHP PHP 5.2.1
Solution:
The vendor has addressed this issue in the latest CVS repository. Contact the vendor for details on obtaining and applying the appropriate updates.
PHP PHP 5.2
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.7
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.7 RC1
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.7 RC3
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.7 RC2
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.1 .0
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.1.1
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.1.2
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.2 -dev
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.2 .0
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.2.1
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.2.2
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.2.3
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.1
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.10
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.11
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.2
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.3
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.4
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.5
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.6
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.7
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.8
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.9
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.4 .0
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.4.1
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.4.2
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.4.3
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.4.4
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.4.5
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.4.6
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.0 .0
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.0 candidate 2
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.0 candidate 3
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.0 candidate 1
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.0.1
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.0.2
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.0.3
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.0.4
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.0.5
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.1
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.1.1
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.1.2
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.1.3 -RC1
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.1.3
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.1.4
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.1.5
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.1.6
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.2.1
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
References
PHP Import_Request_Variables Arbitrary Variable Overwrite Vulnerability
References:
References:
- PHP 4.4.7 Release Announcement (PHP)
- PHP 5.2.2 Release Announcement (PHP)
- PHP Homepage (PHP)
- Php Nuke POST XSS on steroids (ascii)
- Re: [Full-disclosure] PHP import_request_variables() arbitrary variable overwrit (Stefan Esser
) - Re: [Full-disclosure] PHP import_request_variables() arbitrary variable overwrit (ascii
) - PHP import_request_variables() arbitrary variable overwrite (Stefano di Paola)
- SUSE Security Announcement SUSE-SA:2007:044 (SUSE)