5
CVSSv2

CVE-2007-1452

Published: 14/03/2007 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The FDF support (ext/fdf) in PHP 5.2.0 and previous versions does not implement the input filtering hooks for ext/filter, which allows remote malicious users to bypass web site filters via an application/vnd.fdf formatted POST.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 5.0.0

php php 5.0

php php 5.1.0

php php 5.2.0

php php 5.0.2

php php 5.0.3

php php 5.0.4

php php 5.0.5

php php 5.1.1

php php 5.1.2

php php 5.1.3

php php 5.1.4

php php 5.1.5

php php 5.0.1

php php 5.1.6

Exploits

<?php //////////////////////////////////////////////////////////////////////// // _ _ _ _ ___ _ _ ___ // // | || | __ _ _ _ __| | ___ _ _ ___ __| | ___ | _ \| || || _ \ // // | __ |/ _` || '_|/ _` |/ -_)| ' \ / -_)/ _` ||___|| _/| __ || _/ // // |_||_|\__,_||_| \__,_|\___||_||_|\_ ...