CVE-2007-1521
PHP <4.4.7, <5.2.2 - Use After Free
Title source: llmDescription
Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a memory limit violation.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Stefan Esser · phplocallinux
https://www.exploit-db.com/exploits/3479
References (21)
... and 1 more
Scores
EPSS
0.1698
EPSS Percentile
95.0%
Details
Status
published
Products (1)
php/php
< 5.2.1
Published
Mar 20, 2007
Tracked Since
Feb 18, 2026