CVE-2007-3578 Information
Feb 14, 2021
cve
Description
PHPIDS before 20070703 does not properly handle (1) arithmetic expressions and (2) unclosed comments which allows remote attackers to inject arbitrary web script.
Reference
http://groups.google.com/group/php-ids/browse_thread/thread/3ec15f69d6b3dba0 http://osvdb.org/45757 http://osvdb.org/45758 http://sla.ckers.org/forum/read.php?21320913218 https://exchange.xforce.ibmcloud.com/vulnerabilities/35519
Share on: