Record summary

CVE-2007-4586 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

Multiple buffer overflows in php_iisfunc.dll in the iisfunc extension for PHP 5.2.0 and earlier allow context-dependent attackers to execute arbitrary code, probably during Unicode conversion, as demonstrated by a long string in the first argument to the iis_getservicestate function, related to the ServiceId argument to the (1) fnStartService, (2) fnGetServiceState, (3) fnStopService, and possibly other functions.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBPHP 5.2.0 (Windows x86) - 'PHP_iisfunc.dll' Local Buffer OverflowExploitDB exploitby boeckeNot analyzed1 file
ExploitDB

PoC details

References

4