← All CVEs

CVE-2007-1825

high · 7.5

Buffer overflow in the imap_mail_compose function in PHP 5 before 5.2.1, and PHP 4 before 4.4.5, allows remote attackers to execute arbitrary code via a long boundary string in a type.parameters field. NOTE: as of 20070411, it appears that this issue might be subsumed by CVE-2007-0906.3.

7.5
CVSS
10.4%
EPSS (exploit prob.)
96th
EPSS percentile
2007-04-02
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
phpphp4.0.0
phpphp4.0.1
phpphp4.0.1
phpphp4.0.1
phpphp4.0.2
phpphp4.0.3
phpphp4.0.3
phpphp4.0.4
phpphp4.0.4
phpphp4.0.5
phpphp4.0.6
phpphp4.0.7
phpphp4.0.7
phpphp4.0.7
phpphp4.0.7
phpphp4.1.0
phpphp4.1.1
phpphp4.1.2
phpphp4.2
phpphp4.2.0
phpphp4.2.1
phpphp4.2.2
phpphp4.2.3
phpphp4.3.0
phpphp4.3.1
phpphp4.3.2
phpphp4.3.3
phpphp4.3.4
phpphp4.3.5
phpphp4.3.6
phpphp4.3.7
phpphp4.3.8
phpphp4.3.9
phpphp4.3.10
phpphp4.3.11
phpphp4.4.0
phpphp4.4.1
phpphp4.4.2
phpphp4.4.3
phpphp4.4.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-1825