Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.18.28.38.4202120222023202420252026202720282029

Недавние уязвимости PHP

Количество 3 799

nvd логотип

CVE-2009-4017

больше 15 лет назад

PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier for remote attackers to exploit local file inclusion vulnerabilities, via multiple requests, related to lack of support for the max_file_uploads directive.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-4017

больше 15 лет назад

PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-4017

больше 15 лет назад

PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier for remote attackers to exploit local file inclusion vulnerabilities, via multiple requests, related to lack of support for the max_file_uploads directive.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2009-3559

больше 15 лет назад

main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recognize the safe_mode_include_dir directive, which allows context-dependent attackers to have an unknown impact by triggering the failure of PHP scripts that perform include or require operations, as demonstrated by a script that attempts to perform a require_once on a file in a standard library directory. NOTE: a reliable third party reports that this is not a vulnerability, because it results in a more restrictive security policy.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2009-3559

больше 15 лет назад

main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recogn ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-3558

больше 15 лет назад

The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass open_basedir restrictions, and create FIFO files, via the pathname and mode arguments, as demonstrated by creating a .htaccess file.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2009-3558

больше 15 лет назад

The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 an ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2009-3557

больше 15 лет назад

The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix arguments.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-3557

больше 15 лет назад

The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5 ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-3559

больше 15 лет назад

** DISPUTED ** main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recognize the safe_mode_include_dir directive, which allows context-dependent attackers to have an unknown impact by triggering the failure of PHP scripts that perform include or require operations, as demonstrated by a script that attempts to perform a require_once on a file in a standard library directory. NOTE: a reliable third party reports that this is not a vulnerability, because it results in a more restrictive security policy.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2009-4017

PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier for remote attackers to exploit local file inclusion vulnerabilities, via multiple requests, related to lack of support for the max_file_uploads directive.

CVSS2: 5
1%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-4017

PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number ...

CVSS2: 5
1%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2009-4017

PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier for remote attackers to exploit local file inclusion vulnerabilities, via multiple requests, related to lack of support for the max_file_uploads directive.

CVSS2: 5
1%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-3559

main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recognize the safe_mode_include_dir directive, which allows context-dependent attackers to have an unknown impact by triggering the failure of PHP scripts that perform include or require operations, as demonstrated by a script that attempts to perform a require_once on a file in a standard library directory. NOTE: a reliable third party reports that this is not a vulnerability, because it results in a more restrictive security policy.

CVSS2: 7.5
3%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-3559

main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recogn ...

CVSS2: 7.5
3%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-3558

The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass open_basedir restrictions, and create FIFO files, via the pathname and mode arguments, as demonstrated by creating a .htaccess file.

CVSS2: 6.8
4%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-3558

The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 an ...

CVSS2: 6.8
4%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-3557

The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix arguments.

CVSS2: 5
4%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-3557

The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5 ...

CVSS2: 5
4%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2009-3559

** DISPUTED ** main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recognize the safe_mode_include_dir directive, which allows context-dependent attackers to have an unknown impact by triggering the failure of PHP scripts that perform include or require operations, as demonstrated by a script that attempts to perform a require_once on a file in a standard library directory. NOTE: a reliable third party reports that this is not a vulnerability, because it results in a more restrictive security policy.

CVSS2: 7.5
3%
Низкий
больше 15 лет назад

Уязвимостей на страницу


Поделиться