The money_format function in PHP 5 before 5.2.4, and PHP 4 before 4.4.8, permits multiple (1) %i and (2) %n tokens, which has unknown impact and attack vectors, possibly related to a format string vulnerability.
                
            References
                    Configurations
                    Configuration 1 (hide)
                                
                                
  | 
                        
Configuration 2 (hide)
                                
                                
  | 
                        
Information
                Published : 2007-09-04 15:17
Updated : 2018-10-03 14:48
NVD link : CVE-2007-4658
Mitre link : CVE-2007-4658
JSON object : View
CWE
                Products Affected
                php
- php
 


