Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 883

nvd логотип

CVE-2003-0249

около 22 лет назад

PHP treats unknown methods such as "PoSt" as a GET request, which could allow attackers to intended access restrictions if PHP is running on a server that passes on all methods, such as Apache httpd 2.0, as demonstrated using a Limit directive. NOTE: this issue has been disputed by the Apache security team, saying "It is by design that PHP allows scripts to process any request method. A script which does not explicitly verify the request method will hence be processed as normal for arbitrary methods. It is therefore expected behaviour that one cannot implement per-method access control using the Apache configuration alone, which is the assumption made in this report.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2003-0249

около 22 лет назад

PHP treats unknown methods such as "PoSt" as a GET request, which coul ...

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2003-1302

около 22 лет назад

The IMAP functionality in PHP before 4.3.1 allows remote attackers to ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-0863

около 22 лет назад

The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir variable is not specified in configuration, which differs from the previous failure value and may allow remote attackers to exploit file include vulnerabilities in PHP applications.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0861

около 22 лет назад

Integer overflows in (1) base64_encode and (2) the GD library for PHP before 4.3.3 have unknown impact and unknown attack vectors.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2003-0860

около 22 лет назад

Buffer overflows in PHP before 4.3.3 have unknown impact and unknown attack vectors.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2003-0861

около 22 лет назад

Integer overflows in (1) base64_encode and (2) the GD library for PHP ...

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2003-0863

около 22 лет назад

The php_check_safe_mode_include_dir function in fopen_wrappers.c of PH ...

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2003-0860

около 22 лет назад

Buffer overflows in PHP before 4.3.3 have unknown impact and unknown a ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2003-0442

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.

CVSS2: 4.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2003-0249

PHP treats unknown methods such as "PoSt" as a GET request, which could allow attackers to intended access restrictions if PHP is running on a server that passes on all methods, such as Apache httpd 2.0, as demonstrated using a Limit directive. NOTE: this issue has been disputed by the Apache security team, saying "It is by design that PHP allows scripts to process any request method. A script which does not explicitly verify the request method will hence be processed as normal for arbitrary methods. It is therefore expected behaviour that one cannot implement per-method access control using the Apache configuration alone, which is the assumption made in this report.

CVSS2: 7.5
1%
Низкий
около 22 лет назад
debian логотип
CVE-2003-0249

PHP treats unknown methods such as "PoSt" as a GET request, which coul ...

CVSS2: 7.5
1%
Низкий
около 22 лет назад
debian логотип
CVE-2003-1302

The IMAP functionality in PHP before 4.3.1 allows remote attackers to ...

CVSS2: 5
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-0863

The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir variable is not specified in configuration, which differs from the previous failure value and may allow remote attackers to exploit file include vulnerabilities in PHP applications.

CVSS2: 7.5
3%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-0861

Integer overflows in (1) base64_encode and (2) the GD library for PHP before 4.3.3 have unknown impact and unknown attack vectors.

CVSS2: 10
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-0860

Buffer overflows in PHP before 4.3.3 have unknown impact and unknown attack vectors.

CVSS2: 10
0%
Низкий
около 22 лет назад
debian логотип
CVE-2003-0861

Integer overflows in (1) base64_encode and (2) the GD library for PHP ...

CVSS2: 10
1%
Низкий
около 22 лет назад
debian логотип
CVE-2003-0863

The php_check_safe_mode_include_dir function in fopen_wrappers.c of PH ...

CVSS2: 7.5
3%
Низкий
около 22 лет назад
debian логотип
CVE-2003-0860

Buffer overflows in PHP before 4.3.3 have unknown impact and unknown a ...

CVSS2: 10
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-0442

Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.

CVSS2: 4.3
52%
Средний
больше 22 лет назад

Уязвимостей на страницу


Поделиться