PT-2007-4044 · Php · Php

Stefan Esser

·

Published

2007-05-16

·

Updated

2024-08-16

·

CVE-2007-2728

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHP (affected versions not specified)
Description A design error in the make http soap request() function in PHP's soap extension causes it to call php rand r() with an uninitialized variable, potentially leading to weak encryption of sensitive data. This issue could allow attackers to bypass security and gain knowledge of sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2007-2728

Affected Products

Php