Vulnerabilities > CVE-2007-1412 - Local Information Disclosure vulnerability in PHP 4.4.6

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
NONE
Availability impact
NONE
network
low complexity
php
exploit available

Summary

The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensitive information (script source code) via a long string in the second argument.

Vulnerable Configurations

Part Description Count
Application
Php
1

Exploit-Db

descriptionPHP 4.4.6 cpdf_open() Local Source Code Discslosure PoC. CVE-2007-1412. Local exploits for multiple platform
fileexploits/multiple/local/3442.php
idEDB-ID:3442
last seen2016-01-31
modified2007-03-09
platformmultiple
port
published2007-03-09
reporterrgod
sourcehttps://www.exploit-db.com/download/3442/
titlePHP 4.4.6 cpdf_open Local Source Code Discslosure PoC
typelocal

Statements

contributorMark J Cox
lastmodified2007-03-19
organizationRed Hat
statementNot vulnerable. PHP as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and 5 does not include ClibPDF support.