{"api_version":"1","generated_at":"2026-07-23T10:42:40+00:00","cve":"CVE-2007-1522","urls":{"html":"https://cve.report/CVE-2007-1522","api":"https://cve.report/api/cve/CVE-2007-1522.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-1522","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-1522"},"summary":{"title":"CVE-2007-1522","description":"Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which calls the session identifier generator with an improper environment, leading to code execution when the generator is interrupted, as demonstrated by triggering a memory limit violation or certain PHP errors.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-03-20 20:19:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/22971","name":"http://www.securityfocus.com/bid/22971","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP Session Identifier Rejection Double Free Memory Corruption Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.php-security.org/MOPB/MOPB-23-2007.html","name":"http://www.php-security.org/MOPB/MOPB-23-2007.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"MOPB-23-2007:PHP 5 Rejected Session Identifier Double Free Vulnerability","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/25056","name":"http://secunia.com/advisories/25056","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SUSE update for php - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/24505","name":"http://secunia.com/advisories/24505","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP Session Handling Double Free Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.novell.com/linux/security/advisories/2007_32_php.html","name":"http://www.novell.com/linux/security/advisories/2007_32_php.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Announcement","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/0960","name":"http://www.vupen.com/english/advisories/2007/0960","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-1522","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-1522","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"1522","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"php","cpe5":"php","cpe6":"5.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"1522","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"php","cpe5":"php","cpe6":"5.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2007-1522","organization":"Red Hat","lastmodified":"2007-04-16","contributor":"Mark J Cox","statementText":"The PHP interpreter does not offer a reliable &quot;sandboxed&quot; security layer (as found in, say, a JVM) in which untrusted scripts can be run; any script run by the PHP interpreter must be trusted with the privileges of the interpreter itself. We therefore do not classify this issue as security-sensitive since no trust boundary is crossed.","cve_year":"2007","cve_id":"1522","crc32":"3310f798"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:59:08.687Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2007-0960","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/0960"},{"name":"25056","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25056"},{"name":"24505","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/24505"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.php-security.org/MOPB/MOPB-23-2007.html"},{"name":"22971","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/22971"},{"name":"SUSE-SA:2007:032","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://www.novell.com/linux/security/advisories/2007_32_php.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-03-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which calls the session identifier generator with an improper environment, leading to code execution when the generator is interrupted, as demonstrated by triggering a memory limit violation or certain PHP errors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-03-31T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2007-0960","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/0960"},{"name":"25056","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25056"},{"name":"24505","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/24505"},{"tags":["x_refsource_MISC"],"url":"http://www.php-security.org/MOPB/MOPB-23-2007.html"},{"name":"22971","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/22971"},{"name":"SUSE-SA:2007:032","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://www.novell.com/linux/security/advisories/2007_32_php.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-1522","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which calls the session identifier generator with an improper environment, leading to code execution when the generator is interrupted, as demonstrated by triggering a memory limit violation or certain PHP errors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2007-0960","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/0960"},{"name":"25056","refsource":"SECUNIA","url":"http://secunia.com/advisories/25056"},{"name":"24505","refsource":"SECUNIA","url":"http://secunia.com/advisories/24505"},{"name":"http://www.php-security.org/MOPB/MOPB-23-2007.html","refsource":"MISC","url":"http://www.php-security.org/MOPB/MOPB-23-2007.html"},{"name":"22971","refsource":"BID","url":"http://www.securityfocus.com/bid/22971"},{"name":"SUSE-SA:2007:032","refsource":"SUSE","url":"http://www.novell.com/linux/security/advisories/2007_32_php.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-1522","datePublished":"2007-03-20T20:00:00.000Z","dateReserved":"2007-03-20T00:00:00.000Z","dateUpdated":"2024-08-07T12:59:08.687Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-03-20 20:19:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:5.2.0:*:*:*:*:*:*:*","matchCriteriaId":"CD02D837-FD28-4E0F-93F8-25E8D1C84A99"},{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:5.2.1:*:*:*:*:*:*:*","matchCriteriaId":"88358D1E-BE6F-4CE3-A522-83D1FA4739E3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"1522","Ordinal":"1","Title":"CVE-2007-1522","CVE":"CVE-2007-1522","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"1522","Ordinal":"1","NoteData":"Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which calls the session identifier generator with an improper environment, leading to code execution when the generator is interrupted, as demonstrated by triggering a memory limit violation or certain PHP errors.","Type":"Description","Title":"CVE-2007-1522"},{"CveYear":"2007","CveId":"1522","Ordinal":"2","NoteData":"2007-03-20","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"1522","Ordinal":"3","NoteData":"2007-03-31","Type":"Other","Title":"Modified"}]}}}