5.8
CVSSv2

CVE-2007-3790

Published: 15/07/2007 Updated: 29/09/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

The com_print_typeinfo function in the bz2 extension in PHP 5.2.3 allows context-dependent malicious users to cause a denial of service via a long argument.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 5.2.3

Exploits

<?php //PHP 523 bz2 com_print_typeinfo() Remote DoS Exploit //author: shinnai //mail: shinnai[at]autistici[dot]org //site: shinnaialtervistaorg //Tested on xp sp2, worked both from the cli and on apache //Bug discovered with "Footzo" (thanks to rgod) // //To download Footzo: //original link: godraltervistaorg/indexphp?mod ...