|
|

CVE Reference: CVE-2007-1701 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2007-1701 |
|
|
Description: PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables, as demonstrated by calling session_decode on a string beginning with "_SESSION|s:39:". |
|
|
CVE Status: Candidate |
|
|
References: SAID Secunia Advisory: SA25445 Secunia Advisory: SA25423 Secunia Advisory: SA25850 OVAL http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11034 MISC http://www.php-security.org/MOPB/MOPB-31-2007.html HP http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01086137 http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01056506 GENTOO http://security.gentoo.org/glsa/glsa-200705-19.xml BID 23120 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |