AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2016-2049

HIGH · CVSS 8.8 EPSS 2.17%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-02-01 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. It may be remotely exploitable.

CVE
CVE-2016-2049
Severity
HIGH
CVSS
8.8
EPSS
2.17%

Original NVD Description

examples/consumer/common.php in JanRain PHP OpenID library (aka php-openid) improperly checks the openid.realm parameter against the SERVER_NAME element in the SERVER superglobal array, which might allow remote attackers to hijack the authentication of arbitrary users via vectors involving a crafted HTTP Host header.