CVE-2007-0910: Critical severity PHP PHP vulnerability
Published Feb 13, 2007
·Updated
Unspecified vulnerability in PHP before 5.2.1 allows attackers to "clobber" certain super-global variables via unspecified vectors.
Affected Software
77 affected components
PHP PHP=4.3.9
PHP PHP=3.0
PHP PHP=3.0.5
PHP PHP=3.0.11
PHP PHP<=5.2.0
PHP PHP=5.1.5
PHP PHP=5.1.2
PHP PHP=4.2.0
PHP PHP=5.1.1
PHP PHP=3.0.1
PHP PHP=3.0.2
PHP PHP=4.4.4
PHP PHP=4.1.0
PHP PHP=5.1.6
PHP PHP=4.3.4
PHP PHP=4.0.4
PHP PHP=4.3.0
PHP PHP=4.0.5
PHP PHP=5.0-rc1
PHP PHP=3.0.8
PHP PHP=5.0.5
PHP PHP=4.3.6
PHP PHP=3.0.13
PHP PHP=5.0.1
PHP PHP=5.1.4
PHP PHP=4.0.7-rc2
PHP PHP=4.3.7
PHP PHP=5.0.4
PHP PHP=4.0.7-rc1
PHP PHP=4.2.2
PHP PHP=4.4.2
PHP PHP=3.0.7
PHP PHP=4.3.2
PHP PHP=4.3.11
PHP PHP=3.0.6
PHP PHP=4.0.3-patch1
PHP PHP=3.0.17
PHP PHP=4.0.7
PHP PHP=4.0.2
PHP PHP=4.3.3
PHP PHP=5.0-rc3
PHP PHP=4.1.1
PHP PHP=3.0.15
PHP PHP=3.0.16
PHP PHP=4.4.3
PHP PHP=5.0.3
PHP PHP=3.0.10
PHP PHP=3.0.4
PHP PHP=4.2.3
PHP PHP=5.1.0
PHP PHP=4.0.1-patch1
PHP PHP=4.0
PHP PHP=4.0.1-patch2
PHP PHP=4.0.6
PHP PHP=5.0-rc2
PHP PHP=4.1.2
PHP PHP=4.0.7-rc3
PHP PHP=4.3.1
PHP PHP=5.1.3
PHP PHP=3.0.18
PHP PHP=4.4.0
PHP PHP=4.3.10
PHP PHP=4.2.1
PHP PHP=4.0.1
PHP PHP=5.0.2
PHP PHP=3.0.12
PHP PHP=4.2
PHP PHP=4.4.1
PHP PHP=4.0.3
PHP PHP=3.0.14
PHP PHP=3.0.9
PHP PHP=3.0.3
PHP PHP=5.0.0
PHP PHP=4.3.8
PHP PHP=4.3.5
Trustix Secure Linux=3.0
Trustix Secure Linux=2.2
Remediation
Patch Available
Event History
Feb 13, 2007
CVE Published
11:28 PM
Feb 14, 2007
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0910?
CVE-2007-0910 is classified as a moderate severity vulnerability.
2
Which versions of PHP are affected by CVE-2007-0910?
CVE-2007-0910 affects PHP versions 4.0 through 5.2.0.
3
How do I fix CVE-2007-0910?
To fix CVE-2007-0910, upgrade your PHP installation to version 5.2.1 or later.
4
What kind of attacks can exploit CVE-2007-0910?
CVE-2007-0910 can be exploited to overwrite certain super-global variables, potentially leading to unauthorized actions.
5
Is CVE-2007-0910 a remote exploit risk?
Yes, CVE-2007-0910 can be exploited remotely if the affected PHP version is used in a web application.