CVE-2007-1286
PHP <4.4.4 - RCE
Title source: llmDescription
Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long string to the unserialize function, which triggers the overflow in the ZVAL reference counter.
Exploits (4)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16310
exploitdb
WORKING POC
VERIFIED
by Stefan Esser · phpdoslinux
https://www.exploit-db.com/exploits/3396
metasploit
WORKING POC
NORMAL
by hdm · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/php/php_unserialize_zval_cookie.rb
References (32)
... and 12 more
Scores
EPSS
0.8605
EPSS Percentile
99.4%
Details
Status
published
Products (1)
php/php
< 4.4.4
Published
Mar 06, 2007
Tracked Since
Feb 18, 2026