Vulnerabilities > CVE-2005-4731 - Unspecified vulnerability in the PHP Group Pear Html Quickform Controller 1.0.4
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The Next action in PEAR HTML_QuickForm_Controller 1.0.4 includes the SID in the URL even when session.use_only_cookies is configured, which allows remote attackers to obtain the SID via an HTTP Referer field and possibly other vectors.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |