CVE-2007-1701

Published Mar 27, 2007

Last updated 5 years ago

Overview

Description
PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables, as demonstrated by calling session_decode on a string beginning with "_SESSION|s:39:".
Source
cve@mitre.org
NVD status
Modified

Social media

Hype score
Not currently trending

Risk scores

CVSS 2.0

Type
Primary
Base score
6.8
Impact score
6.4
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:P/I:P/A:P

Weaknesses

nvd@nist.gov
CWE-502

Evaluator

Comment
-
Impact
Successful exploitation requires that variable "register_globals" is enabled.
Solution
Successful exploitation requires that variable "register_globals" is enabled.

Vendor comments

  • Red HatThis CVE name is a duplicate as the vulnerability is addressed by CVE-2007-0910.

Configurations