CVE-2007-1701
Php < 4.4.5 - Insecure Deserialization
Title source: ruleDescription
PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables, as demonstrated by calling session_decode on a string beginning with "_SESSION|s:39:".
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Stefan Esser · phplocallinux
https://www.exploit-db.com/exploits/3572
References (12)
Scores
EPSS
0.1097
EPSS Percentile
93.5%
Details
CWE
CWE-502
Status
published
Products (1)
php/php
4.0.0 - 4.4.5
Published
Mar 27, 2007
Tracked Since
Feb 18, 2026