Directory Traversal Vulnerability in Zend Platform by Zend Technologies
CVE-2006-4432

Currently unrated

Key Information:

Vendor

Zend

Vendor
CVE Published:
29 August 2006

What is CVE-2006-4432?

A directory traversal vulnerability in Zend Platform versions 2.2.1 and earlier allows remote attackers to exploit a flaw in the PHP session identifier (PHPSESSID). By crafting a malicious PHPSESSID using a '..' (dot dot) sequence, an attacker can overwrite arbitrary files on the server. This issue poses a significant risk, as it could potentially lead to direct static code injection, thereby compromising the integrity of the web application.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.