CVE-2007-1701

Php < 4.4.5 - Insecure Deserialization

Title source: rule

Description

PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables, as demonstrated by calling session_decode on a string beginning with "_SESSION|s:39:".

Exploits (1)

exploitdb WORKING POC VERIFIED
by Stefan Esser · phplocallinux
https://www.exploit-db.com/exploits/3572

Scores

EPSS 0.1097
EPSS Percentile 93.5%

Details

CWE
CWE-502
Status published
Products (1)
php/php 4.0.0 - 4.4.5
Published Mar 27, 2007
Tracked Since Feb 18, 2026