CVE-2007-1382

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/03/2007
Last modified:
09/04/2025

Description

The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demonstrated by using the Run method of this object to execute cmd.exe, which bypasses PHP's safe mode.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:microsoft:all_windows:abstract_cpe:*:*:*:*:*:*:*
cpe:2.3:a:php:com_extensions:*:*:*:*:*:*:*:*