CVE-2007-1380
PHP <4.4.5, <5.2.1 - Info Disclosure
Title source: llmDescription
The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-dependent attackers to obtain sensitive information (memory contents) via a serialized variable entry with a large length value, which triggers a buffer over-read.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Stefan Esser · phplocalmultiple
https://www.exploit-db.com/exploits/3413
References (22)
... and 2 more
Scores
EPSS
0.1420
EPSS Percentile
94.4%
Details
Status
published
Products (35)
php/php
4.0 (8 CPE variants)
php/php
4.0.0
php/php
4.0.1 (3 CPE variants)
php/php
4.0.2
php/php
4.0.3 (2 CPE variants)
php/php
4.0.4 (2 CPE variants)
php/php
4.0.5
php/php
4.0.6
php/php
4.0.7 (4 CPE variants)
php/php
4.1.0
... and 25 more
Published
Mar 10, 2007
Tracked Since
Feb 18, 2026