Vulnerability Name: | CVE-2007-1287 (CCN-32868) | ||||||||
Assigned: | 2007-03-03 | ||||||||
Published: | 2007-03-03 | ||||||||
Updated: | 2011-03-08 | ||||||||
Summary: | A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP 6.0 in CVS, allows remote attackers to conduct cross-site scripting (XSS) attacks via GET, POST, or COOKIE array values, which are not escaped in the phpinfo output, as originally fixed for CVE-2005-3388. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-1287 Source: CCN Type: Apple Security Update 2007-007 About Security Update 2007-007 Source: CONFIRM Type: UNKNOWN http://docs.info.apple.com/article.html?artnum=306172 Source: CCN Type: Apple Web site Apple security updates Source: APPLE Type: UNKNOWN APPLE-SA-2007-07-31 Source: CCN Type: SA26235 Mac OS X Security Update Fixes Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 26235 Source: CONFIRM Type: UNKNOWN http://us2.php.net/releases/4_4_7.php Source: OSVDB Type: UNKNOWN 32774 Source: CCN Type: OSVDB ID: 32774 PHP phpinfo() Multiple Method User Supplied Array XSS Source: CCN Type: MOPB-08-2007 PHP 4 phpinfo() XSS Vulnerability (Deja-vu) Source: MISC Type: Exploit, Patch, Vendor Advisory http://www.php-security.org/MOPB/MOPB-08-2007.html Source: CCN Type: PHP Web site PHP: Hypertext Preprocessor Source: CCN Type: BID-22803 PHP PHPInfo Cross-Site Scripting Variant Vulnerability Source: BID Type: UNKNOWN 25159 Source: CCN Type: BID-25159 Apple Mac OS X 2007-007 Multiple Security Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2007-2732 Source: XF Type: UNKNOWN php-phpinfofunction-xss(32868) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |