CVE-2007-4010

Publication date 26 July 2007

Last updated 17 July 2025


Ubuntu priority

Description

The win32std extension in PHP 5.2.3 does not follow safe_mode and disable_functions restrictions, which allows remote attackers to execute arbitrary commands via the win_shell_execute function.

Status

Package Ubuntu Release Status
php5 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected