First published: Sat Mar 10 2007(Updated: )
The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demonstrated by using the Run method of this object to execute cmd.exe, which bypasses PHP's safe mode.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows | =abstract_cpe | |
PHP COM Extensions |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1382 is considered to have a high severity due to the potential for remote code execution.
To fix CVE-2007-1382, it is recommended to upgrade to a version of PHP that does not include the vulnerable COM extensions functionality.
CVE-2007-1382 specifically affects PHP COM extensions on Windows systems.
Yes, attackers can exploit CVE-2007-1382 remotely by leveraging the WScript.Shell COM object.
No, safe mode is ineffective against CVE-2007-1382 as the vulnerability allows bypassing it.