6.8
CVSSv2

CVE-2007-1583

Published: 21/03/2007 Updated: 30/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The mb_parse_str function in PHP 4.0.0 up to and including 4.4.6 and 5.0.0 up to and including 5.2.1 sets the internal register_globals flag and does not disable it in certain cases when a script terminates, which allows remote malicious users to invoke available PHP scripts with register_globals functionality that is not detectable by these scripts, as demonstrated by forcing a memory_limit violation.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 4.0.1

php php 4.0.5

php php 4.0.6

php php 4.0

php php 4.2.1

php php 4.2.2

php php 4.3.2

php php 4.3.3

php php 4.4.1

php php 4.4.2

php php 5.0.0

php php 5.0.3

php php 5.0.4

php php 5.1.2

php php 5.1.3

php php 4.0.3

php php 4.0.7

php php 4.1.0

php php 4.1.1

php php 4.3.0

php php 4.3.1

php php 4.3.6

php php 4.3.7

php php 4.3.8

php php 4.4.5

php php 4.4.6

php php 5.0

php php 5.1.0

php php 5.1.6

php php 5.2.0

php php 4.0.2

php php 4.2.3

php php 4.2

php php 4.3.4

php php 4.3.5

php php 4.4.3

php php 4.4.4

php php 5.0.5

php php 5.1.4

php php 5.1.5

php php 4.0.0

php php 4.0.4

php php 4.1.2

php php 4.2.0

php php 4.3.10

php php 4.3.11

php php 4.3.9

php php 4.4.0

php php 5.0.1

php php 5.0.2

php php 5.1.1

php php 5.2.1

Vendor Advisories

Stefan Esser discovered multiple vulnerabilities in the “Month of PHP bugs” ...
Several remote vulnerabilities have been discovered in PHP, a server-side, HTML-embedded scripting language, which may lead to the execution of arbitrary code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-1286 Stefan Esser discovered an overflow in the object reference handling code of the un ...

Exploits

source: wwwsecurityfocuscom/bid/23016/info PHP is prone to a weakness that allows attackers to enable the 'register_globals' directive because the application fails to handle a memory-limit exception Enabling the PHP 'register_globals' directive may allow attackers to further exploit latent vulnerabilities in PHP scripts This issue is ...

References

NVD-CWE-Otherhttp://www.php-security.org/MOPB/MOPB-26-2007.htmlhttp://www.securityfocus.com/bid/23016http://rhn.redhat.com/errata/RHSA-2007-0155.htmlhttp://secunia.com/advisories/24924https://issues.rpath.com/browse/RPL-1268http://www.redhat.com/support/errata/RHSA-2007-0153.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0162.htmlhttp://secunia.com/advisories/24965http://secunia.com/advisories/24945http://www.debian.org/security/2007/dsa-1283http://www.ubuntu.com/usn/usn-455-1http://secunia.com/advisories/25062http://us2.php.net/releases/4_4_7.phphttp://us2.php.net/releases/5_2_2.phphttp://secunia.com/advisories/25057http://secunia.com/advisories/24909http://docs.info.apple.com/article.html?artnum=306172http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.htmlhttp://security.gentoo.org/glsa/glsa-200705-19.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:088http://www.mandriva.com/security/advisories?name=MDKSA-2007:089http://www.mandriva.com/security/advisories?name=MDKSA-2007:090http://www.novell.com/linux/security/advisories/2007_32_php.htmlhttp://www.securityfocus.com/bid/25159http://secunia.com/advisories/25056http://secunia.com/advisories/25445http://secunia.com/advisories/26235http://www.vupen.com/english/advisories/2007/2732https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10245http://www.securityfocus.com/archive/1/466166/100/0/threadedhttps://usn.ubuntu.com/455-1/https://nvd.nist.govhttps://www.exploit-db.com/exploits/29752/