VYPR

Tidy extension

by PHP

CVEs (1)

  • CVE-2007-3294Jun 20, 2007
    risk 0.04cvss epss 0.09

    Multiple buffer overflows in libtidy, as used in the Tidy extension for PHP 5.2.3 and possibly other products, allow context-dependent attackers to execute arbitrary code via (1) a long second argument to the tidy_parse_string function or (2) an unspecified vector to the…