CVE-2007-1521

PHP <4.4.7, <5.2.2 - Use After Free

Title source: llm

Description

Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a memory limit violation.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Stefan Esser · phplocallinux
https://www.exploit-db.com/exploits/3479

Scores

EPSS 0.1698
EPSS Percentile 95.0%

Details

Status published
Products (1)
php/php < 5.2.1
Published Mar 20, 2007
Tracked Since Feb 18, 2026