'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2016-5385: PHP HTTP_PROXY Enviroment Variables Vulnerability
Severity:mid
CVE ID:CVE-2016-5385
| Descripiton:
|
PHP(Hypertext Preprocessor) is a kind of widely used open source languages. PHP is mainly used for Web development because of easily being embedded into HTML. Because of namespace conflicts in PHP(version < 7.0.8), client inputs are failed to filtered by HTTP_PROXY. Remote attackers may redirect HTTP streams to any proxy server by constructing Proxy header in HTTP request, leading to HTTPOXY attack. See more at https://httpoxy.org/. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.