CVE-2007-1287 is a regression error in the phpinfo function of PHP versions 4.4.3 through 4.4.6, and PHP 6.0 in CVS, allowing remote attackers to perform Cross-Site Scripting (XSS) attacks. This vulnerability arises because GET, POST, or COOKIE array values are not properly escaped in the phpinfo output, reintroducing a flaw previously addressed in CVE-2005-3388. Rated with a CVSS score of 4.3, this vulnerability has a network attack vector and medium attack complexity, potentially leading to information disclosure (partial impact) without requiring authentication. Its FAUCET Risk Score is 91/100, indicating a significant risk despite a relatively low CVSS score. While not listed on the CISA KEV catalog, exploit code is publicly available via ExploitDB (EDB-3405). There is no evidence of active exploitation, and community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.4.4CPE matchmatch criteria | cpe:2.3:a:php:php:4.4.4:*:*:*:*:*:*:* | ||
4.4.5CPE matchmatch criteria | cpe:2.3:a:php:php:4.4.5:*:*:*:*:*:*:* | ||
4.4.6CPE matchmatch criteria | cpe:2.3:a:php:php:4.4.6:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:php:php:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.