PT-2007-4044 · Php · Php

·

CVE-2007-2728

·

Publicado

2007-05-16

·

Atualizado

2024-08-16

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHP (affected versions not specified)
Description A design error in the make http soap request() function in PHP's soap extension causes it to call php rand r() with an uninitialized variable, potentially leading to weak encryption of sensitive data. This issue could allow attackers to bypass security and gain knowledge of sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2728

Produtos afetados

Php