Logo
vulnerabilityCVE-2007-3205
Name
CVE-2007-3205
Source
NVD ( link)Debian ( link)
Description
The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin.
CWEs
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
php8
Exploitable

Vulnerability Rating#


5
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
8.3.31
Exploitable
buildroot
master
8.5.7
Exploitable
openwrt
openwrt-25.12
8.4.21-r1
Exploitable
yocto
kirkstone
8.1.34
Not Affected
yocto
master
8.5.7
Not Affected
yocto
scarthgap
8.2.31
Not Affected