First published: Thu Jul 26 2007(Updated: )
The win32std extension in PHP 5.2.3 does not follow safe_mode and disable_functions restrictions, which allows remote attackers to execute arbitrary commands via the win_shell_execute function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP | =5.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4010 is classified as a critical vulnerability due to its potential to allow remote command execution.
To fix CVE-2007-4010, upgrade PHP to a version higher than 5.2.3 that does not contain this vulnerability.
CVE-2007-4010 affects PHP version 5.2.3.
CVE-2007-4010 allows remote attackers to execute arbitrary commands on the server, posing a significant security risk.
No, CVE-2007-4010 bypasses safe_mode restrictions, rendering it ineffective in mitigating this vulnerability.