SB2018103066 - Multiple vulnerabilities in PHP



SB2018103066 - Multiple vulnerabilities in PHP

Published: October 30, 2018 Updated: June 8, 2025

Security Bulletin ID SB2018103066
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Medium 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Format string error (CVE-ID: CVE-2006-0200)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.


2) Code Injection (CVE-ID: CVE-2006-0207)

The vulnerability allows a remote non-authenticated attacker to corrupt data.

Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.


Remediation

Install update from vendor's website.