Unknown
CVE-2016-5385
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2016-5385
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application’s outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv(‘HTTP_PROXY’) call or (2) a CGI configuration of PHP, aka an “httpoxy” issue.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
- debian,
- drupal,
- fedoraproject,
- hp,
- opensuse,
- oracle,
- php,
- redhat
Products
- communications user data repository 10.0.0,
- communications user data repository 10.0.1,
- communications user data repository 12.0.0,
- debian linux 8.0,
- drupal,
- enterprise linux desktop 6.0,
- enterprise linux server 6.0,
- enterprise linux workstation 6.0,
- enterprise manager ops center 12.2.2,
- enterprise manager ops center 12.3.2,
- fedora 23,
- fedora 24,
- leap 42.1,
- linux 6,
- linux 7,
- php,
- storeever msl6480 tape library firmware,
- system management homepage
References
Advisory
Miscellaneous
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: