{"id":"DEBIAN-CVE-2007-5934","details":"The LOB functionality in PEAR MDB2 before 2.5.0a1 interprets a request to store a URL string as a request to retrieve and store the contents of the URL, which might allow remote attackers to use MDB2 as an indirect proxy or obtain sensitive information via a URL into a form field in an MDB2 application, as demonstrated by a file:// URL or a URL for an intranet web site.","modified":"2026-09-01T20:02:49.530849634Z","published":"2007-11-13T22:46:00Z","upstream":["CVE-2007-5934"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2007-5934"}],"affected":[{"package":{"name":"php-mdb2","ecosystem":"Debian:12","purl":"pkg:deb/debian/php-mdb2?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.0b2-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2007-5934.json"}}],"schema_version":"1.9.0"}