CVE-2007-1382: Medium severity Microsoft All Windows vulnerability
Published Mar 10, 2007
·Updated
The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demonstrated by using the Run method of this object to execute cmd.exe, which bypasses PHP's safe mode.
Affected Software
2 affected components
Microsoft All Windows=abstract_cpe
PHP COM extensions
Event History
Mar 10, 2007
CVE Published
12:19 AM
Data Sourced
12:19 AM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1382?
CVE-2007-1382 is considered to have a high severity due to the potential for remote code execution.
2
How do I fix CVE-2007-1382?
To fix CVE-2007-1382, it is recommended to upgrade to a version of PHP that does not include the vulnerable COM extensions functionality.
3
What systems are affected by CVE-2007-1382?
CVE-2007-1382 specifically affects PHP COM extensions on Windows systems.
4
Can CVE-2007-1382 be exploited remotely?
Yes, attackers can exploit CVE-2007-1382 remotely by leveraging the WScript.Shell COM object.
5
Is safe mode effective against CVE-2007-1382?
No, safe mode is ineffective against CVE-2007-1382 as the vulnerability allows bypassing it.