CVE-2007-1454

Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 14 Mar 2007, 18:00
Last modified:07 Aug 2024, 12:59

Vulnerability Summary

Overall Risk (default)
low
17/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
0.49% LOW
0% probability +0.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Mar 2007, 18:00
Published
Vulnerability first disclosed
07 Aug 2024, 12:59
Last Modified
Vulnerability information updated

Description

ext/filter in PHP 5.2.0, when FILTER_SANITIZE_STRING is used with the FILTER_FLAG_STRIP_LOW flag, does not properly strip HTML tags, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML with a '<' character followed by certain whitespace characters, which passes one filter but is collapsed into a valid tag, as demonstrated using %0b.

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 0.49% Percentile: 66%

Affected Systems

  • UnknownPHP

    5.2.0

References (7)