Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4 000

Количество 4 000

redhat логотип

CVE-2010-1130

больше 16 лет назад

session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the session_save_path function, which allows context-dependent attackers to bypass open_basedir and safe_mode restrictions via an argument that contains multiple ; characters in conjunction with a .. (dot dot).

EPSS: Низкий
nvd логотип

CVE-2010-1130

больше 16 лет назад

session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the session_save_path function, which allows context-dependent attackers to bypass open_basedir and safe_mode restrictions via an argument that contains multiple ; characters in conjunction with a .. (dot dot).

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2010-1130

больше 16 лет назад

session.c in the session extension in PHP before 5.2.13, and 5.3.1, do ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2010-1129

больше 16 лет назад

The safe_mode implementation in PHP before 5.2.13 does not properly handle directory pathnames that lack a trailing / (slash) character, which allows context-dependent attackers to bypass intended access restrictions via vectors related to use of the tempnam function.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2010-1129

больше 16 лет назад

The safe_mode implementation in PHP before 5.2.13 does not properly handle directory pathnames that lack a trailing / (slash) character, which allows context-dependent attackers to bypass intended access restrictions via vectors related to use of the tempnam function.

EPSS: Низкий
nvd логотип

CVE-2010-1129

больше 16 лет назад

The safe_mode implementation in PHP before 5.2.13 does not properly handle directory pathnames that lack a trailing / (slash) character, which allows context-dependent attackers to bypass intended access restrictions via vectors related to use of the tempnam function.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2010-1129

больше 16 лет назад

The safe_mode implementation in PHP before 5.2.13 does not properly ha ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2010-1128

больше 16 лет назад

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

CVSS2: 6.4
EPSS: Низкий
redhat логотип

CVE-2010-1128

больше 16 лет назад

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2010-1128

больше 16 лет назад

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2010-1128

больше 16 лет назад

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2010-0397

больше 16 лет назад

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2010-0397

больше 16 лет назад

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2010-0397

больше 16 лет назад

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2010-0397

больше 16 лет назад

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing m ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2009-5016

больше 15 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2009-5016

почти 17 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-5016

больше 15 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2009-5016

больше 15 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in P ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2009-4418

больше 16 лет назад

The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2010-1130

session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the session_save_path function, which allows context-dependent attackers to bypass open_basedir and safe_mode restrictions via an argument that contains multiple ; characters in conjunction with a .. (dot dot).

9%
Низкий
больше 16 лет назад
nvd логотип
CVE-2010-1130

session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the session_save_path function, which allows context-dependent attackers to bypass open_basedir and safe_mode restrictions via an argument that contains multiple ; characters in conjunction with a .. (dot dot).

CVSS2: 5
9%
Низкий
больше 16 лет назад
debian логотип
CVE-2010-1130

session.c in the session extension in PHP before 5.2.13, and 5.3.1, do ...

CVSS2: 5
9%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2010-1129

The safe_mode implementation in PHP before 5.2.13 does not properly handle directory pathnames that lack a trailing / (slash) character, which allows context-dependent attackers to bypass intended access restrictions via vectors related to use of the tempnam function.

CVSS2: 7.5
3%
Низкий
больше 16 лет назад
redhat логотип
CVE-2010-1129

The safe_mode implementation in PHP before 5.2.13 does not properly handle directory pathnames that lack a trailing / (slash) character, which allows context-dependent attackers to bypass intended access restrictions via vectors related to use of the tempnam function.

3%
Низкий
больше 16 лет назад
nvd логотип
CVE-2010-1129

The safe_mode implementation in PHP before 5.2.13 does not properly handle directory pathnames that lack a trailing / (slash) character, which allows context-dependent attackers to bypass intended access restrictions via vectors related to use of the tempnam function.

CVSS2: 7.5
3%
Низкий
больше 16 лет назад
debian логотип
CVE-2010-1129

The safe_mode implementation in PHP before 5.2.13 does not properly ha ...

CVSS2: 7.5
3%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2010-1128

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

CVSS2: 6.4
8%
Низкий
больше 16 лет назад
redhat логотип
CVE-2010-1128

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

CVSS2: 2.6
8%
Низкий
больше 16 лет назад
nvd логотип
CVE-2010-1128

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

CVSS2: 6.4
8%
Низкий
больше 16 лет назад
debian логотип
CVE-2010-1128

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not ...

CVSS2: 6.4
8%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2010-0397

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

CVSS2: 5
12%
Средний
больше 16 лет назад
redhat логотип
CVE-2010-0397

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

CVSS2: 4.3
12%
Средний
больше 16 лет назад
nvd логотип
CVE-2010-0397

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

CVSS2: 5
12%
Средний
больше 16 лет назад
debian логотип
CVE-2010-0397

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing m ...

CVSS2: 5
12%
Средний
больше 16 лет назад
ubuntu логотип
CVE-2009-5016

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

CVSS2: 6.8
3%
Низкий
больше 15 лет назад
redhat логотип
CVE-2009-5016

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

CVSS2: 4.3
3%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-5016

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

CVSS2: 6.8
3%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-5016

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in P ...

CVSS2: 6.8
3%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2009-4418

The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.

CVSS2: 5
1%
Низкий
больше 16 лет назад

Уязвимостей на страницу