PT-2007-2777 · Php · Php

Publicado

2007-03-10

·

Atualizado

2017-10-11

·

CVE-2007-1382

CVSS v2.0

6.8

Média

VetorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHP COM extensions for PHP on Windows systems (affected versions not specified)
Description The issue allows context-dependent attackers to execute arbitrary code via a WScript.Shell COM object. This can be demonstrated by using the Run method of this object to execute cmd.exe, which bypasses PHP's safe mode.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-1382

Produtos afetados

Php