VDB

CVE-2007-4658

CVE-2007-4658 PUBLISHED CVSS 7.5 HIGH

The money_format function in PHP 5 before 5.2.4, and PHP 4 before 4.4.8, permits multiple (1) %i and (2) %n tokens, which has unknown impact and attack vectors, possibly related to a format string vulnerability.

EPSS 4.01% · 88.7th percentile

Risk Scores

CVSS 2.0
7.5
EPSS Score
4.01%
88.7th percentile

Affected Products

VendorProductVersions
phpphp4.0, 5.0.0, 5.0.0
n/an/a*

Exploit Intelligence

…and 28 more exploits

Timeline

  • Sep 4, 2007 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
  • Sep 8, 2023 EPSS Score
  • Oct 30, 2023 EPSS Score

References

…and 21 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›