CVE-2007-1286

PHP <4.4.4 - RCE

Title source: llm

Description

Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long string to the unserialize function, which triggers the overflow in the ZVAL reference counter.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16310
exploitdb WORKING POC VERIFIED
by Stefan Esser · phpdoslinux
https://www.exploit-db.com/exploits/3396
exploitdb WORKING POC VERIFIED
by sesser · rubyremotephp
https://www.exploit-db.com/exploits/9939
metasploit WORKING POC NORMAL
by hdm · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/php/php_unserialize_zval_cookie.rb

References (32)

... and 12 more

Scores

EPSS 0.8605
EPSS Percentile 99.4%

Details

Status published
Products (1)
php/php < 4.4.4
Published Mar 06, 2007
Tracked Since Feb 18, 2026