PHP Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2015-8935 - Vulnerability Database

PHP Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2015-8935

Medium
Reference: CVE-2015-8935
Title: PHP Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

The sapi_header_op function in main/SAPI.c in PHP before 5.4.38 5.5.x before 5.5.22 and 5.6.x before 5.6.6 supports deprecated line folding without considering browser compatibility which allows remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer by leveraging (1) 0A20 or (2) 0D0A20 mishandling in the header function.