CVE-2007-4010

PHP <5.2.3 - Command Injection

Title source: llm

Description

The win32std extension in PHP 5.2.3 does not follow safe_mode and disable_functions restrictions, which allows remote attackers to execute arbitrary commands via the win_shell_execute function.

Exploits (1)

exploitdb WORKING POC VERIFIED
by shinnai · phplocalwindows
https://www.exploit-db.com/exploits/4218

Scores

EPSS 0.0416
EPSS Percentile 88.7%

Details

Status published
Products (1)
php/php 5.2.3
Published Jul 26, 2007
Tracked Since Feb 18, 2026