CVE-2007-1522
PHP 5.2.0/5.2.1 - Rejected Session ID Double-Free
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which calls the session identifier generator with an improper environment, leading to code execution when the generator is interrupted, as demonstrated by triggering a memory limit violation or certain PHP errors.
Vulnerabilidad de liberación doble en la extensión session de PHP 5.2.0 and 5.2.1 permite a atacantes dependientes del contexto ejecutar código de su elección mediante caracteres ilegales en el identificador de sesión, lo cual es rechazado por el módulo de almacenamiento de sesión interno, lo cual llama al generador de identificador de sesión en un contexto inapropiado, dando la posibilidad de la inyección de código cuando el generador es interrumpido, como ha sido demostrado lanzando una violación de límite de memoria o ciertos errores de PHP.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-03-14 First Exploit
- 2007-03-20 CVE Reserved
- 2007-03-20 CVE Published
- 2024-06-23 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/24505 | Third Party Advisory | |
http://secunia.com/advisories/25056 | Third Party Advisory | |
http://www.securityfocus.com/bid/22971 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/0960 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/3480 | 2007-03-14 | |
http://www.php-security.org/MOPB/MOPB-23-2007.html | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.novell.com/linux/security/advisories/2007_32_php.html | 2011-03-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Php Search vendor "Php" | Php Search vendor "Php" for product "Php" | 5.2.0 Search vendor "Php" for product "Php" and version "5.2.0" | - |
Affected
| ||||||
Php Search vendor "Php" | Php Search vendor "Php" for product "Php" | 5.2.1 Search vendor "Php" for product "Php" and version "5.2.1" | - |
Affected
|