PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an applications outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv(HTTP_PROXY) call or (2) a CGI configuration of PHP, aka an httpoxy issue.
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Communications_user_data_repository | Oracle | 10.0.0 (including) | 10.0.0 (including) |
Communications_user_data_repository | Oracle | 10.0.1 (including) | 10.0.1 (including) |
Communications_user_data_repository | Oracle | 12.0.0 (including) | 12.0.0 (including) |
Enterprise_manager_ops_center | Oracle | 12.2.2 (including) | 12.2.2 (including) |
Enterprise_manager_ops_center | Oracle | 12.3.2 (including) | 12.3.2 (including) |
Linux | Oracle | 6 (including) | 6 (including) |
Linux | Oracle | 7 (including) | 7 (including) |
Red Hat Enterprise Linux 6 | RedHat | php-0:5.3.3-48.el6_8 | * |
Red Hat Enterprise Linux 7 | RedHat | php-0:5.4.16-36.3.el7_2 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | php54-php-0:5.4.40-4.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | php55-php-0:5.5.21-5.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | rh-php56-php-0:5.6.5-9.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | RedHat | php54-php-0:5.4.40-4.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | RedHat | php55-php-0:5.5.21-5.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | RedHat | rh-php56-php-0:5.6.5-9.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | php54-php-0:5.4.40-4.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | php55-php-0:5.5.21-5.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | rh-php56-php-0:5.6.5-9.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | php54-php-0:5.4.40-4.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | php55-php-0:5.5.21-5.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-php56-php-0:5.6.5-9.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS | RedHat | php54-php-0:5.4.40-4.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS | RedHat | php55-php-0:5.5.21-5.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS | RedHat | rh-php56-php-0:5.6.5-9.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | RedHat | php54-php-0:5.4.40-4.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | RedHat | php55-php-0:5.5.21-5.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | RedHat | rh-php56-php-0:5.6.5-9.el7 | * |
Php5 | Ubuntu | precise | * |
Php5 | Ubuntu | trusty | * |
Php5 | Ubuntu | wily | * |
Php7.0 | Ubuntu | devel | * |
Php7.0 | Ubuntu | upstream | * |
Php7.0 | Ubuntu | xenial | * |