7.5
CVSSv2

CVE-2007-1885

Published: 06/04/2007 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the str_replace function in PHP 4 prior to 4.4.5 and PHP 5 prior to 5.2.1 allows context-dependent malicious users to execute arbitrary code via a single character search string in conjunction with a long replacement string, which overflows a 32 bit length counter. NOTE: this is probably the same issue as CVE-2007-0906.6.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 4.0.1

php php 4.0.2

php php 4.0.7

php php 4.2.1

php php 4.2.2

php php 4.3.3

php php 4.3.4

php php 4.4.1

php php 4.0.3

php php 4.2.3

php php 4.2

php php 4.3.5

php php 4.3.6

php php 4.4.3

php php 4.4.4

php php 5.0.0

php php 5.0

php php 5.1.4

php php 5.1.5

php php 4.0.4

php php 4.1.0

php php 4.1.1

php php 4.3.0

php php 4.3.1

php php 4.3.7

php php 4.3.8

php php 4.4.5

php php 4.4.6

php php 5.0.1

php php 5.1.0

php php 5.1.6

php php 5.2.0

php php 4.4.2

php php 5.0.4

php php 5.0.5

php php 5.1.2

php php 5.1.3

php php 4.0.0

php php 4.0.5

php php 4.0.6

php php 4.1.2

php php 4.2.0

php php 4.3.10

php php 4.3.11

php php 4.3.2

php php 4.3.9

php php 4.4.0

php php 5.0.2

php php 5.0.3

php php 5.1.1