Количество 34
Количество 34
BDU:2024-07679
Уязвимость сценария cgi.force_redirect интерпретатора языка программирования PHP, позволяющая нарушителю обойти существующие ограничения безопасности
ROS-20241015-15
Множественные уязвимости php
ROS-20241015-14
Множественные уязвимости php
ROS-20241015-11
Множественные уязвимости php
ALT-PU-2024-18047
ALT-PU-2024-18047: package `php8.1-soap` update to version 8.1.30-alt1
ALT-PU-2024-17955
ALT-PU-2024-17955: package `php8.3-soap` update to version 8.3.12-alt1
ALT-PU-2024-17951
ALT-PU-2024-17951: package `php8.1-soap` update to version 8.1.30-alt1
ALT-PU-2024-17912
ALT-PU-2024-17912: package `php8.2-soap` update to version 8.2.24-alt1
ALT-PU-2024-13710
ALT-PU-2024-13710: package `php8.1` update to version 8.1.30-alt1
ALT-PU-2024-13522
ALT-PU-2024-13522: package `php8.1` update to version 8.1.30-alt1
ALT-PU-2024-13465
ALT-PU-2024-13465: package `php8.2` update to version 8.2.24-alt1
ALT-PU-2024-13449
ALT-PU-2024-13449: package `php8.3` update to version 8.3.12-alt1
ALT-PU-2024-18037
ALT-PU-2024-18037: package `php8.2-soap` update to version 8.2.24-alt1
ALT-PU-2024-13711
ALT-PU-2024-13711: package `php8.2` update to version 8.2.24-alt1
ALT-PU-2021-2943
ALT-PU-2021-2943: package `php7` update to version 7.4.24-alt1
CVE-2024-8927
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.
CVE-2024-8927
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.
CVE-2024-8927
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.
CVE-2024-8927
cgi.force_redirect configuration is bypassable due to the environment variable collision
CVE-2024-8927
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2024-07679 Уязвимость сценария cgi.force_redirect интерпретатора языка программирования PHP, позволяющая нарушителю обойти существующие ограничения безопасности | CVSS3: 9.8 | 1% Низкий | почти 2 года назад | |
ROS-20241015-15 Множественные уязвимости php | CVSS3: 9.8 | почти 2 года назад | ||
ROS-20241015-14 Множественные уязвимости php | CVSS3: 9.8 | почти 2 года назад | ||
ROS-20241015-11 Множественные уязвимости php | CVSS3: 9.8 | почти 2 года назад | ||
ALT-PU-2024-18047 ALT-PU-2024-18047: package `php8.1-soap` update to version 8.1.30-alt1 | CVSS3: 9.8 | почти 2 года назад | ||
ALT-PU-2024-17955 ALT-PU-2024-17955: package `php8.3-soap` update to version 8.3.12-alt1 | CVSS3: 9.8 | почти 2 года назад | ||
ALT-PU-2024-17951 ALT-PU-2024-17951: package `php8.1-soap` update to version 8.1.30-alt1 | CVSS3: 9.8 | почти 2 года назад | ||
ALT-PU-2024-17912 ALT-PU-2024-17912: package `php8.2-soap` update to version 8.2.24-alt1 | CVSS3: 9.8 | почти 2 года назад | ||
ALT-PU-2024-13710 ALT-PU-2024-13710: package `php8.1` update to version 8.1.30-alt1 | CVSS3: 9.8 | почти 2 года назад | ||
ALT-PU-2024-13522 ALT-PU-2024-13522: package `php8.1` update to version 8.1.30-alt1 | CVSS3: 9.8 | почти 2 года назад | ||
ALT-PU-2024-13465 ALT-PU-2024-13465: package `php8.2` update to version 8.2.24-alt1 | CVSS3: 9.8 | почти 2 года назад | ||
ALT-PU-2024-13449 ALT-PU-2024-13449: package `php8.3` update to version 8.3.12-alt1 | CVSS3: 9.8 | почти 2 года назад | ||
ALT-PU-2024-18037 ALT-PU-2024-18037: package `php8.2-soap` update to version 8.2.24-alt1 | CVSS3: 9.8 | почти 2 года назад | ||
ALT-PU-2024-13711 ALT-PU-2024-13711: package `php8.2` update to version 8.2.24-alt1 | CVSS3: 9.8 | почти 2 года назад | ||
ALT-PU-2021-2943 ALT-PU-2021-2943: package `php7` update to version 7.4.24-alt1 | CVSS3: 9.8 | почти 5 лет назад | ||
CVE-2024-8927 In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP. | CVSS3: 7.5 | 1% Низкий | почти 2 года назад | |
CVE-2024-8927 In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP. | CVSS3: 7.5 | 1% Низкий | почти 2 года назад | |
CVE-2024-8927 In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP. | CVSS3: 7.5 | 1% Низкий | почти 2 года назад | |
CVE-2024-8927 cgi.force_redirect configuration is bypassable due to the environment variable collision | CVSS3: 7.5 | 1% Низкий | почти 2 года назад | |
CVE-2024-8927 In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before ... | CVSS3: 7.5 | 1% Низкий | почти 2 года назад |
Уязвимостей на страницу