Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-1701 | First vendor Publication | 2007-03-26 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.8 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables, as demonstrated by calling session_decode on a string beginning with "_SESSION|s:39:". |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1701 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-502 | Deserialization of Untrusted Data |
OVAL Definitions
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2012-06-21 | Name : PHP version smaller than 4.4.5 File : nvt/nopsec_php_4_4_5.nasl |
2012-06-21 | Name : PHP version smaller than 5.2.1 File : nvt/nopsec_php_5_2_1.nasl |
2010-04-23 | Name : PHP Session Data Deserialization Arbitrary Code Execution Vulnerability File : nvt/gb_php_23120.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200705-19 (php) File : nvt/glsa_200705_19.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
33945 | PHP _SESSION Deserialization Global Variable Overwrite PHP contains a flaw that may allow a context-dependent attacker to gain elevated privileges. The issue is due to the ability of the deserialization of session data to overwrite arbitrary global variables. This can allow an attacker to execute arbitrary code. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2007-0076.nasl - Type : ACT_GATHER_INFO |
2007-05-29 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200705-19.nasl - Type : ACT_GATHER_INFO |
2007-05-25 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2007-0082.nasl - Type : ACT_GATHER_INFO |
2007-04-02 | Name : The remote web server uses a version of PHP that is affected by multiple flaws. File : php_4_4_5.nasl - Type : ACT_GATHER_INFO |
2007-04-02 | Name : The remote web server uses a version of PHP that is affected by multiple flaws. File : php_5_2_1.nasl - Type : ACT_GATHER_INFO |
2007-02-23 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2007-0081.nasl - Type : ACT_GATHER_INFO |
2007-02-21 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2007-0076.nasl - Type : ACT_GATHER_INFO |
2007-02-21 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2007-0076.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:17:50 |
|
2024-11-28 12:11:53 |
|
2024-08-02 12:06:35 |
|
2024-08-02 01:02:14 |
|
2024-02-02 01:06:14 |
|
2024-02-01 12:02:14 |
|
2023-09-05 12:05:49 |
|
2023-09-05 01:02:05 |
|
2023-09-02 12:05:54 |
|
2023-09-02 01:02:06 |
|
2023-08-12 12:06:54 |
|
2023-08-12 01:02:06 |
|
2023-08-11 12:05:58 |
|
2023-08-11 01:02:10 |
|
2023-08-06 12:05:40 |
|
2023-08-06 01:02:07 |
|
2023-08-04 12:05:46 |
|
2023-08-04 01:02:10 |
|
2023-07-14 12:05:45 |
|
2023-07-14 01:02:08 |
|
2023-03-29 01:06:25 |
|
2023-03-28 12:02:13 |
|
2022-10-11 12:05:05 |
|
2022-10-11 01:01:58 |
|
2021-05-04 12:05:53 |
|
2021-04-22 01:06:25 |
|
2020-05-23 01:38:00 |
|
2020-05-23 00:19:30 |
|
2019-10-10 05:19:25 |
|
2019-06-08 12:02:03 |
|
2019-03-19 12:02:24 |
|
2018-11-30 12:02:02 |
|
2018-10-20 00:19:37 |
|
2018-10-04 12:04:39 |
|
2017-10-11 09:23:54 |
|
2017-07-29 12:02:07 |
|
2016-10-05 01:00:31 |
|
2016-06-28 16:19:36 |
|
2016-04-26 15:55:36 |
|
2014-02-17 10:39:37 |
|
2013-05-11 10:21:49 |
|
2012-11-07 00:14:32 |
|