Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 883

ubuntu логотип

CVE-2006-1014

почти 20 лет назад

Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 3.2
EPSS: Низкий
ubuntu логотип

CVE-2006-1015

почти 20 лет назад

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2006-0208

около 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2006-0200

около 20 лет назад

Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.

CVSS2: 9.3
EPSS: Средний
nvd логотип

CVE-2006-0207

около 20 лет назад

Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2006-0200

около 20 лет назад

Format string vulnerability in the error-reporting feature in the mysq ...

CVSS2: 9.3
EPSS: Средний
debian логотип

CVE-2006-0208

около 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5 ...

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2006-0207

около 20 лет назад

Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow re ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-0200

около 20 лет назад

Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.

CVSS2: 9.3
EPSS: Средний
ubuntu логотип

CVE-2006-0207

около 20 лет назад

Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2006-1014

Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 3.2
2%
Низкий
почти 20 лет назад
ubuntu логотип
CVE-2006-1015

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 6.4
8%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-0208

Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.

CVSS2: 2.6
2%
Низкий
около 20 лет назад
nvd логотип
CVE-2006-0200

Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.

CVSS2: 9.3
12%
Средний
около 20 лет назад
nvd логотип
CVE-2006-0207

Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.

CVSS2: 5
4%
Низкий
около 20 лет назад
debian логотип
CVE-2006-0200

Format string vulnerability in the error-reporting feature in the mysq ...

CVSS2: 9.3
12%
Средний
около 20 лет назад
debian логотип
CVE-2006-0208

Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5 ...

CVSS2: 2.6
2%
Низкий
около 20 лет назад
debian логотип
CVE-2006-0207

Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow re ...

CVSS2: 5
4%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2006-0200

Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.

CVSS2: 9.3
12%
Средний
около 20 лет назад
ubuntu логотип
CVE-2006-0207

Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.

CVSS2: 5
4%
Низкий
около 20 лет назад

Уязвимостей на страницу


Поделиться