DEBIAN-CVE-2007-5934

Source
https://security-tracker.debian.org/tracker/CVE-2007-5934
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2007-5934.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2007-5934
Upstream
Published
2007-11-13T22:46:00Z
Modified
2026-04-28T20:09:51.779594Z
Summary
[none]
Details

The LOB functionality in PEAR MDB2 before 2.5.0a1 interprets a request to store a URL string as a request to retrieve and store the contents of the URL, which might allow remote attackers to use MDB2 as an indirect proxy or obtain sensitive information via a URL into a form field in an MDB2 application, as demonstrated by a file:// URL or a URL for an intranet web site.

References

Affected packages

Debian:11 / php-mdb2

Package

Name
php-mdb2
Purl
pkg:deb/debian/php-mdb2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.5.0b2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2007-5934.json"

Debian:12 / php-mdb2

Package

Name
php-mdb2
Purl
pkg:deb/debian/php-mdb2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.5.0b2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2007-5934.json"