Unrated severityNVD Advisory· Published Aug 29, 2006· Updated Apr 16, 2026
CVE-2006-4432
CVE-2006-4432
Description
Directory traversal vulnerability in Zend Platform 2.2.1 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the final component of the PHP session identifier (PHPSESSID). NOTE: in some cases, this issue can be leveraged to perform direct static code injection.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- secunia.com/advisories/21573nvdPatchVendor Advisory
- www.hardened-php.net/advisory_052006.128.htmlnvdPatchVendor Advisory
- securityreason.com/securityalert/1466nvd
- www.osvdb.org/28232nvd
- www.securityfocus.com/archive/1/444263/100/0/threadednvd
- www.vupen.com/english/advisories/2006/3388nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/28576nvd
News mentions
0No linked articles in our index yet.