Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 4 010

redhat логотип

CVE-2012-4388

около 14 лет назад

The sapi_header_op function in main/SAPI.c in PHP 5.4.0RC2 through 5.4.0 does not properly determine a pointer during checks for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1398.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-1398

около 14 лет назад

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5. ...

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2011-1398

около 14 лет назад

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome.

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2011-1398

около 14 лет назад

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2012-3450

около 14 лет назад

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x ...

CVSS2: 2.6
EPSS: Средний
nvd логотип

CVE-2012-3450

около 14 лет назад

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.

CVSS2: 2.6
EPSS: Средний
ubuntu логотип

CVE-2012-3450

около 14 лет назад

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.

CVSS2: 2.6
EPSS: Средний
debian логотип

CVE-2012-3365

около 14 лет назад

The SQLite functionality in PHP before 5.3.15 allows remote attackers ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-3365

около 14 лет назад

The SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-2688

около 14 лет назад

Unspecified vulnerability in the _php_stream_scandir function in the s ...

CVSS2: 10
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2012-4388

The sapi_header_op function in main/SAPI.c in PHP 5.4.0RC2 through 5.4.0 does not properly determine a pointer during checks for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1398.

CVSS2: 4.3
4%
Низкий
около 14 лет назад
debian логотип
CVE-2011-1398

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5. ...

CVSS2: 4.3
10%
Средний
около 14 лет назад
nvd логотип
CVE-2011-1398

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome.

CVSS2: 4.3
10%
Средний
около 14 лет назад
ubuntu логотип
CVE-2011-1398

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome.

CVSS2: 4.3
10%
Средний
около 14 лет назад
debian логотип
CVE-2012-3450

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x ...

CVSS2: 2.6
11%
Средний
около 14 лет назад
nvd логотип
CVE-2012-3450

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.

CVSS2: 2.6
11%
Средний
около 14 лет назад
ubuntu логотип
CVE-2012-3450

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.

CVSS2: 2.6
11%
Средний
около 14 лет назад
debian логотип
CVE-2012-3365

The SQLite functionality in PHP before 5.3.15 allows remote attackers ...

CVSS2: 5
3%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-3365

The SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors.

CVSS2: 5
3%
Низкий
около 14 лет назад
debian логотип
CVE-2012-2688

Unspecified vulnerability in the _php_stream_scandir function in the s ...

CVSS2: 10
10%
Средний
около 14 лет назад

Уязвимостей на страницу


Поделиться