Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-1711. PoCs published by Stefan Esser.
AI-analyzed exploit summary This exploit targets a double-free vulnerability in PHP's session_decode() function (CVE-2007-1711) by manipulating session variables to trigger memory corruption. It demonstrates arbitrary memory manipulation via destructor pointer overwriting.
Description
Double free vulnerability in the unserializer in PHP 4.4.5 and 4.4.6 allows context-dependent attackers to execute arbitrary code by overwriting variables pointing to (1) the GLOBALS array or (2) the session data in _SESSION. NOTE: this issue was introduced when attempting to patch CVE-2007-1701 (MOPB-31-2007).
Exploits (1)
This exploit targets a double-free vulnerability in PHP's session_decode() function (CVE-2007-1711) by manipulating session variables to trigger memory corruption. It demonstrates arbitrary memory manipulation via destructor pointer overwriting.