PHP Other Vulnerability - CVE-2007-1454 - Vulnerability Database

PHP Other Vulnerability - CVE-2007-1454

Medium
Reference: CVE-2007-1454
Title: PHP Other Vulnerability
Overview:

ext/filter in PHP 5.2.0 when FILTER_SANITIZE_STRING is used with the FILTER_FLAG_STRIP_LOW flag does not properly strip HTML tags which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML with a 39lt39 character followed by certain whitespace characters which passes one filter but is collapsed into a valid tag as demonstrated using 0b.