CVE-2007-3806 describes a denial-of-service vulnerability in the glob function of PHP 5.2.3, potentially leading to arbitrary code execution. This flaw arises from an invalid flags parameter value, likely due to memory corruption or an invalid read on Windows platforms, and possibly an uninitialized glob structure. With a CVSS score of 6.8, this vulnerability is considered medium severity, requiring network access and medium attack complexity to achieve partial confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an ExploitDB entry (EDB-4181) exists for a denial-of-service exploit, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2.3CPE matchmatch criteria | cpe:2.3:a:php:php:5.2.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.