Логотип exploitDog
bind:"CVE-2012-2688" OR bind:"CVE-2011-1398" OR bind:"CVE-2012-0831"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2012-2688" OR bind:"CVE-2011-1398" OR bind:"CVE-2012-0831"

Количество 19

Количество 19

oracle-oval логотип

ELSA-2013-0514

больше 12 лет назад

ELSA-2013-0514: php security, bug fix and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2013-1307

больше 11 лет назад

ELSA-2013-1307: php53 security, bug fix and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2013-1814

больше 11 лет назад

ELSA-2013-1814: php security update (CRITICAL)

EPSS: Низкий
ubuntu логотип

CVE-2012-2688

почти 13 лет назад

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

CVSS2: 10
EPSS: Средний
redhat логотип

CVE-2012-2688

почти 13 лет назад

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

CVSS2: 4.4
EPSS: Средний
nvd логотип

CVE-2012-2688

почти 13 лет назад

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2012-2688

почти 13 лет назад

Unspecified vulnerability in the _php_stream_scandir function in the s ...

CVSS2: 10
EPSS: Средний
github логотип

GHSA-5xf9-hrqg-23cp

около 3 лет назад

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

EPSS: Средний
fstec логотип

BDU:2022-02620

почти 13 лет назад

Уязвимость функции _php_stream_scandir интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.1
EPSS: Средний
ubuntu логотип

CVE-2012-0831

больше 13 лет назад

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c.

CVSS2: 6.8
EPSS: Средний
redhat логотип

CVE-2012-0831

больше 13 лет назад

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c.

CVSS2: 2.6
EPSS: Средний
nvd логотип

CVE-2012-0831

больше 13 лет назад

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c.

CVSS2: 6.8
EPSS: Средний
debian логотип

CVE-2012-0831

больше 13 лет назад

PHP before 5.3.10 does not properly perform a temporary change to the ...

CVSS2: 6.8
EPSS: Средний
ubuntu логотип

CVE-2011-1398

почти 13 лет назад

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2011-1398

больше 13 лет назад

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2011-1398

почти 13 лет назад

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2011-1398

почти 13 лет назад

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5. ...

CVSS2: 4.3
EPSS: Средний
github логотип

GHSA-p39c-84x2-h365

около 3 лет назад

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c.

EPSS: Средний
github логотип

GHSA-g6fq-45x6-cmh4

около 3 лет назад

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2013-0514

ELSA-2013-0514: php security, bug fix and enhancement update (MODERATE)

больше 12 лет назад
oracle-oval логотип
ELSA-2013-1307

ELSA-2013-1307: php53 security, bug fix and enhancement update (MODERATE)

больше 11 лет назад
oracle-oval логотип
ELSA-2013-1814

ELSA-2013-1814: php security update (CRITICAL)

больше 11 лет назад
ubuntu логотип
CVE-2012-2688

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

CVSS2: 10
37%
Средний
почти 13 лет назад
redhat логотип
CVE-2012-2688

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

CVSS2: 4.4
37%
Средний
почти 13 лет назад
nvd логотип
CVE-2012-2688

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

CVSS2: 10
37%
Средний
почти 13 лет назад
debian логотип
CVE-2012-2688

Unspecified vulnerability in the _php_stream_scandir function in the s ...

CVSS2: 10
37%
Средний
почти 13 лет назад
github логотип
GHSA-5xf9-hrqg-23cp

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

37%
Средний
около 3 лет назад
fstec логотип
BDU:2022-02620

Уязвимость функции _php_stream_scandir интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.1
37%
Средний
почти 13 лет назад
ubuntu логотип
CVE-2012-0831

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c.

CVSS2: 6.8
15%
Средний
больше 13 лет назад
redhat логотип
CVE-2012-0831

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c.

CVSS2: 2.6
15%
Средний
больше 13 лет назад
nvd логотип
CVE-2012-0831

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c.

CVSS2: 6.8
15%
Средний
больше 13 лет назад
debian логотип
CVE-2012-0831

PHP before 5.3.10 does not properly perform a temporary change to the ...

CVSS2: 6.8
15%
Средний
больше 13 лет назад
ubuntu логотип
CVE-2011-1398

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome.

CVSS2: 4.3
10%
Средний
почти 13 лет назад
redhat логотип
CVE-2011-1398

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome.

CVSS2: 4.3
10%
Средний
больше 13 лет назад
nvd логотип
CVE-2011-1398

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome.

CVSS2: 4.3
10%
Средний
почти 13 лет назад
debian логотип
CVE-2011-1398

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5. ...

CVSS2: 4.3
10%
Средний
почти 13 лет назад
github логотип
GHSA-p39c-84x2-h365

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c.

15%
Средний
около 3 лет назад
github логотип
GHSA-g6fq-45x6-cmh4

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome.

10%
Средний
около 3 лет назад

Уязвимостей на страницу