Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 883

nvd логотип

CVE-2009-4418

около 16 лет назад

The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-4418

около 16 лет назад

The unserialize function in PHP 5.3.0 and earlier allows context-depen ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-4418

около 16 лет назад

The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2009-4143

около 16 лет назад

PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2009-4143

около 16 лет назад

PHP before 5.2.12 does not properly handle session data, which has uns ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2009-4142

около 16 лет назад

The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2009-4142

около 16 лет назад

The htmlspecialchars function in PHP before 5.2.12 does not properly h ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2009-4142

около 16 лет назад

The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2009-4143

около 16 лет назад

PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.

CVSS2: 10
EPSS: Низкий
redhat логотип

CVE-2009-4143

около 16 лет назад

PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2009-4418

The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.

CVSS2: 5
0%
Низкий
около 16 лет назад
debian логотип
CVE-2009-4418

The unserialize function in PHP 5.3.0 and earlier allows context-depen ...

CVSS2: 5
0%
Низкий
около 16 лет назад
ubuntu логотип
CVE-2009-4418

The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.

CVSS2: 5
0%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-4143

PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.

CVSS2: 10
8%
Низкий
около 16 лет назад
debian логотип
CVE-2009-4143

PHP before 5.2.12 does not properly handle session data, which has uns ...

CVSS2: 10
8%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-4142

The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.

CVSS2: 4.3
17%
Средний
около 16 лет назад
debian логотип
CVE-2009-4142

The htmlspecialchars function in PHP before 5.2.12 does not properly h ...

CVSS2: 4.3
17%
Средний
около 16 лет назад
ubuntu логотип
CVE-2009-4142

The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.

CVSS2: 4.3
17%
Средний
около 16 лет назад
ubuntu логотип
CVE-2009-4143

PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.

CVSS2: 10
8%
Низкий
около 16 лет назад
redhat логотип
CVE-2009-4143

PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.

8%
Низкий
около 16 лет назад

Уязвимостей на страницу


Поделиться