The money_format function in PHP 5 before 5.2.4, and PHP 4 before 4.4.8, permits multiple (1) %i and (2) %n tokens, which has unknown impact and attack vectors, possibly related to a format string vulnerability.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2007-09-04 15:17
Updated : 2018-10-03 14:48
NVD link : CVE-2007-4658
Mitre link : CVE-2007-4658
JSON object : View
CWE
Products Affected
php
- php