CVE-2007-1452 Information

Share on:

Description

The FDF support (ext/fdf) in PHP 5.2.0 and earlier does not implement the input filtering hooks for ext/filter which allows remote attackers to bypass web site filters via an application/vnd.fdf formatted POST.

Reference

http://www.php-security.org/MOPB/MOPB-17-2007.html http://www.securityfocus.com/bid/22906