PHPIDS does not properly handle certain code containing newlines, as demonstrated by a try/catch block within a loop, which allows user-assisted remote attackers to inject arbitrary web script.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpids | Phpids | * | * |