Skip to main content

PHP SSL Client Certificate Verification and Session Fixation Vulnerabilities

Last Update Date: 20 Aug 2013 12:43 Release Date: 20 Aug 2013 3948 Views

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

Multiple vulnerabilities have been identified in PHP, which can be exploited by malicious people to conduct spoofing and session hijacking attacks.


Impact

  • Spoofing

System / Technologies affected

  • PHP 5.4.x
  • PHP 5.5.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 5.5.2

Vulnerability Identifier


Source


Related Link