Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-8935


The sapi_header_op function in main/SAPI.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 supports deprecated line folding without considering browser compatibility, which allows remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer by leveraging (1) %0A%20 or (2) %0D%0A%20 mishandling in the header function.


Published

2016-08-07T10:59:01.320

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 6.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application php php ≤ 5.4.37 Yes
Application php php 5.5.0 Yes
Application php php 5.5.0 Yes
Application php php 5.5.0 Yes
Application php php 5.5.0 Yes
Application php php 5.5.0 Yes
Application php php 5.5.0 Yes
Application php php 5.5.0 Yes
Application php php 5.5.0 Yes
Application php php 5.5.0 Yes
Application php php 5.5.0 Yes
Application php php 5.5.0 Yes
Application php php 5.5.0 Yes
Application php php 5.5.0 Yes
Application php php 5.5.1 Yes
Application php php 5.5.2 Yes
Application php php 5.5.3 Yes
Application php php 5.5.4 Yes
Application php php 5.5.5 Yes
Application php php 5.5.6 Yes
Application php php 5.5.7 Yes
Application php php 5.5.8 Yes
Application php php 5.5.9 Yes
Application php php 5.5.10 Yes
Application php php 5.5.11 Yes
Application php php 5.5.12 Yes
Application php php 5.5.13 Yes
Application php php 5.5.14 Yes
Application php php 5.5.18 Yes
Application php php 5.5.19 Yes
Application php php 5.5.20 Yes
Application php php 5.5.21 Yes
Application php php 5.6.0 Yes
Application php php 5.6.0 Yes
Application php php 5.6.0 Yes
Application php php 5.6.0 Yes
Application php php 5.6.0 Yes
Application php php 5.6.0 Yes
Application php php 5.6.0 Yes
Application php php 5.6.0 Yes
Application php php 5.6.0 Yes
Application php php 5.6.1 Yes
Application php php 5.6.2 Yes
Application php php 5.6.3 Yes
Application php php 5.6.4 Yes
Application php php 5.6.5 Yes

References