Innovate faster and cut risk with PHP experts from Zend Services.
Explore Services
See How Zend Helps Leading Hosting Providers Keep Their Managed Sites on Secure PHP
Read More
Learn PHP from PHP experts with free, on-demand, and instructor led courses.
Explore Training
Submit support requests and browse self-service resources.
Explore Support
Host/Secure cookie bypass due to partial CVE-2022-31629 -5955')) ORDER BY 1-- seus
Due to an incomplete fix for CVE-2022-31629, network and same-site attackers can set a standard insecure cookie in the victim's browser, which is then treated as a __Host- or __Secure- cookie by PHP applications.
__Host-
__Secure-
If you use Same-Site cookies, we recommend updating to a patched version of PHP.
Direct link to CVE-2024-2756 >
< View all CVEs