CVE-2007-1711
PHP 4.4.5-4.4.6 - Use After Free
Title source: llmDescription
Double free vulnerability in the unserializer in PHP 4.4.5 and 4.4.6 allows context-dependent attackers to execute arbitrary code by overwriting variables pointing to (1) the GLOBALS array or (2) the session data in _SESSION. NOTE: this issue was introduced when attempting to patch CVE-2007-1701 (MOPB-31-2007).
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Stefan Esser · phpdoslinux
https://www.exploit-db.com/exploits/3586
References (26)
... and 6 more
Scores
EPSS
0.1543
EPSS Percentile
94.7%
Details
Status
published
Products (2)
php/php
4.4.5
php/php
4.4.6
Published
Mar 27, 2007
Tracked Since
Feb 18, 2026