Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment." http://www.hardened-php.net/advisory_182005.77.html This issue should also affect RHEL2.1 and RHEL3
A POC for this issue has been posted to full-disclosure: http://marc.theaimsgroup.com/?l=full-disclosure&m=113110346903765&w=2 phpinfo.php?GLOBALS[test]=<script>alert(document.cookie);</script>
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2005-831.html
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2005-838.html