MEDIUM · 5.0

CVE-2007-3205

The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names...

Vulnerability Description

The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
Hardened-Php ProjectHardened-PhpAll versions
Hardened-Php ProjectSubhosinAll versions
PhpPhpAll versions

References

FAQ

What is CVE-2007-3205?

CVE-2007-3205 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names...

How severe is CVE-2007-3205?

CVE-2007-3205 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-3205?

Check the references section above for vendor advisories and patch information. Affected products include: Hardened-Php Project Hardened-Php, Hardened-Php Project Subhosin, Php Php.