VDB

CVE-2007-4658

CVE-2007-4658 PUBLISHED CVSS 7.5 HIGH

The money_format function in PHP 5 before 5.2.4, and PHP 4 before 4.4.8, permits multiple (1) %i and (2) %n tokens, which has unknown impact and attack vectors, possibly related to a format string vulnerability.

EPSS 2.03% · 80.1th percentile

Risk Scores

CVSS 2.0
7.5
EPSS Score
2.03%
80.1th percentile

Affected Products

VendorProductVersions
phpphp4.0, 5.0.0, 5.0.0
n/an/a*

Timeline

  • Sep 4, 2007 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 13, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Dec 20, 2022 EPSS Score
  • Feb 11, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • May 29, 2023 EPSS Score
  • Jul 21, 2023 EPSS Score
  • Sep 12, 2023 EPSS Score
  • Dec 27, 2023 EPSS Score

References

…and 21 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›