← All CVEs

CVE-2007-3806

medium · 6.8

The glob function in PHP 5.2.3 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via an invalid value of the flags parameter, probably related to memory corruption or an invalid read on win32 platforms, and possibly related to lack of initialization for a glob structure.

6.8
CVSS
10.7%
EPSS (exploit prob.)
96th
EPSS percentile
2007-07-17
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Weaknesses

CWE-20CWE-399

Affected products

VendorProductAffected versions
phpphp5.2.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-3806