Description
The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demonstrated by using the Run method of this object to execute cmd.exe, which bypasses PHP's safe mode.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2007-1378 | The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demonstrated by using the Run method of this object to execute cmd.exe, which bypasses PHP's safe mode. |
References
| Link | Providers |
|---|---|
| https://www.exploit-db.com/exploits/3429 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T12:50:35.265Z
Reserved: 2007-03-09T00:00:00.000Z
Link: CVE-2007-1382
No data.
Status : Deferred
Published: 2007-03-10T00:19:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2007-1382
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD