peter bassill · operator
$ cve CVE-2007-3806 JSON

CVE-2007-3806 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 10.7% (pctl 96)

Patch early

A public exploit exists.

Description

The glob function in PHP 5.2.3 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via an invalid value of the flags parameter, probably related to memory corruption or an invalid read on win32 platforms, and possibly related to lack of initialization for a glob structure.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS10.74% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2007-07-17
Last modified2026-06-16

Affected (1)

VendorProduct
phpphp

Public exploits

SourceTitleDate
exploit-dbPHP 5.2.3 - 'glob()' Denial of Service2007-07-14

References

→ the Explorer  ·  watch your stack  ·  NVD