CVE-2007-4658 PUBLISHED CVSS 7.5 HIGH

The money_format function in PHP 5 before 5.2.4, and PHP 4 before 4.4.8, permits multiple (1) %i and (2) %n tokens, which has unknown impact and attack vectors, possibly related to a format string vulnerability.

EPSS 3.38% · 87.3th percentile

Risk Scores

CVSS v2.0
7.5
EPSS Score
3.38%
87.3th percentile

Affected Products

VendorProductVersions
phpphp4.4.7, 5.0.0, 5.0.0
n/an/an/a

Timeline

References

…and 21 more

Open in Interactive Console →