[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-1649Date: (C)2007-03-23   (M)2024-02-22


PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a serialized data input string beginning with S:, which does not properly track the number of input bytes being processed.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.8
Exploit Score: 10.0
Impact Score: 6.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: NONE
Availability: NONE
  
Reference:
BID-23105
SECUNIA-24630
MDVSA-2008:126
http://us2.php.net/releases/5_2_2.php
http://www.php-security.org/MOPB/MOPB-29-2007.html
php-unserialize-information-disclosure(33170)

CPE    1
cpe:/a:php:php:5.2.1
OVAL    1
oval:org.secpod.oval:def:301343

© SecPod Technologies