Files
cve/2010/CVE-2010-3065.md
2025-09-29 21:09:30 +02:00

708 B

CVE-2010-3065

Description

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.

POC

Reference

No PoCs from references.

Github