Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 889

Количество 3 889

nvd логотип

CVE-2008-0599

почти 18 лет назад

The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2008-0599

почти 18 лет назад

The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5. ...

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2008-0145

около 18 лет назад

Unspecified vulnerability in glob in PHP before 4.4.8, when open_basedir is enabled, has unknown impact and attack vectors. NOTE: this issue reportedly exists because of a regression related to CVE-2007-4663.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-0145

около 18 лет назад

Unspecified vulnerability in glob in PHP before 4.4.8, when open_basedir is enabled, has unknown impact and attack vectors. NOTE: this issue reportedly exists because of a regression related to CVE-2007-4663.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-0145

около 18 лет назад

Unspecified vulnerability in glob in PHP before 4.4.8, when open_based ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2007-6039

больше 18 лет назад

PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in (1) the domain parameter to the dgettext function, the message parameter to the (2) dcgettext or (3) gettext function, the msgid1 parameter to the (4) dngettext or (5) ngettext function, or (6) the classname parameter to the stream_wrapper_register function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless this issue can be demonstrated for code execution.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2007-6039

больше 18 лет назад

PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in (1) the domain parameter to the dgettext function, the message parameter to the (2) dcgettext or (3) gettext function, the msgid1 parameter to the (4) dngettext or (5) ngettext function, or (6) the classname parameter to the stream_wrapper_register function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless this issue can be demonstrated for code execution.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2007-6039

больше 18 лет назад

PHP 5.2.5 and earlier allows context-dependent attackers to cause a de ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2007-5900

больше 18 лет назад

PHP before 5.2.5 allows local users to bypass protection mechanisms configured through php_admin_value or php_admin_flag in httpd.conf by using ini_set to modify arbitrary configuration variables, a different issue than CVE-2006-4625.

CVSS2: 6.9
EPSS: Низкий
nvd логотип

CVE-2007-5900

больше 18 лет назад

PHP before 5.2.5 allows local users to bypass protection mechanisms configured through php_admin_value or php_admin_flag in httpd.conf by using ini_set to modify arbitrary configuration variables, a different issue than CVE-2006-4625.

CVSS2: 6.9
EPSS: Низкий
debian логотип

CVE-2007-5900

больше 18 лет назад

PHP before 5.2.5 allows local users to bypass protection mechanisms co ...

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2007-5899

больше 18 лет назад

The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2007-5899

больше 18 лет назад

The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID.

EPSS: Низкий
nvd логотип

CVE-2007-5899

больше 18 лет назад

The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2007-5899

больше 18 лет назад

The output_add_rewrite_var function in PHP before 5.2.5 rewrites local ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-5898

больше 18 лет назад

The (1) htmlentities and (2) htmlspecialchars functions in PHP before 5.2.5 accept partial multibyte sequences, which has unknown impact and attack vectors, a different issue than CVE-2006-5465.

CVSS2: 6.4
EPSS: Низкий
redhat логотип

CVE-2007-5898

больше 18 лет назад

The (1) htmlentities and (2) htmlspecialchars functions in PHP before 5.2.5 accept partial multibyte sequences, which has unknown impact and attack vectors, a different issue than CVE-2006-5465.

EPSS: Низкий
nvd логотип

CVE-2007-5898

больше 18 лет назад

The (1) htmlentities and (2) htmlspecialchars functions in PHP before 5.2.5 accept partial multibyte sequences, which has unknown impact and attack vectors, a different issue than CVE-2006-5465.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2007-5898

больше 18 лет назад

The (1) htmlentities and (2) htmlspecialchars functions in PHP before ...

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2007-5653

больше 18 лет назад

The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by executing objects with the kill bit set in the corresponding ActiveX control Compatibility Flags, executing programs via a function in compatUI.dll, invoking wscript.shell via wscript.exe, invoking Scripting.FileSystemObject via wshom.ocx, and adding users via a function in shgina.dll, related to the com_load_typelib function.

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2008-0599

The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.

CVSS3: 9.8
39%
Средний
почти 18 лет назад
debian логотип
CVE-2008-0599

The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5. ...

CVSS3: 9.8
39%
Средний
почти 18 лет назад
ubuntu логотип
CVE-2008-0145

Unspecified vulnerability in glob in PHP before 4.4.8, when open_basedir is enabled, has unknown impact and attack vectors. NOTE: this issue reportedly exists because of a regression related to CVE-2007-4663.

CVSS2: 7.5
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-0145

Unspecified vulnerability in glob in PHP before 4.4.8, when open_basedir is enabled, has unknown impact and attack vectors. NOTE: this issue reportedly exists because of a regression related to CVE-2007-4663.

CVSS2: 7.5
1%
Низкий
около 18 лет назад
debian логотип
CVE-2008-0145

Unspecified vulnerability in glob in PHP before 4.4.8, when open_based ...

CVSS2: 7.5
1%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2007-6039

PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in (1) the domain parameter to the dgettext function, the message parameter to the (2) dcgettext or (3) gettext function, the msgid1 parameter to the (4) dngettext or (5) ngettext function, or (6) the classname parameter to the stream_wrapper_register function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless this issue can be demonstrated for code execution.

CVSS2: 2.1
0%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-6039

PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in (1) the domain parameter to the dgettext function, the message parameter to the (2) dcgettext or (3) gettext function, the msgid1 parameter to the (4) dngettext or (5) ngettext function, or (6) the classname parameter to the stream_wrapper_register function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless this issue can be demonstrated for code execution.

CVSS2: 2.1
0%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-6039

PHP 5.2.5 and earlier allows context-dependent attackers to cause a de ...

CVSS2: 2.1
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-5900

PHP before 5.2.5 allows local users to bypass protection mechanisms configured through php_admin_value or php_admin_flag in httpd.conf by using ini_set to modify arbitrary configuration variables, a different issue than CVE-2006-4625.

CVSS2: 6.9
0%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-5900

PHP before 5.2.5 allows local users to bypass protection mechanisms configured through php_admin_value or php_admin_flag in httpd.conf by using ini_set to modify arbitrary configuration variables, a different issue than CVE-2006-4625.

CVSS2: 6.9
0%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-5900

PHP before 5.2.5 allows local users to bypass protection mechanisms co ...

CVSS2: 6.9
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-5899

The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID.

CVSS2: 4.3
2%
Низкий
больше 18 лет назад
redhat логотип
CVE-2007-5899

The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID.

2%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-5899

The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID.

CVSS2: 4.3
2%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-5899

The output_add_rewrite_var function in PHP before 5.2.5 rewrites local ...

CVSS2: 4.3
2%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-5898

The (1) htmlentities and (2) htmlspecialchars functions in PHP before 5.2.5 accept partial multibyte sequences, which has unknown impact and attack vectors, a different issue than CVE-2006-5465.

CVSS2: 6.4
6%
Низкий
больше 18 лет назад
redhat логотип
CVE-2007-5898

The (1) htmlentities and (2) htmlspecialchars functions in PHP before 5.2.5 accept partial multibyte sequences, which has unknown impact and attack vectors, a different issue than CVE-2006-5465.

6%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-5898

The (1) htmlentities and (2) htmlspecialchars functions in PHP before 5.2.5 accept partial multibyte sequences, which has unknown impact and attack vectors, a different issue than CVE-2006-5465.

CVSS2: 6.4
6%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-5898

The (1) htmlentities and (2) htmlspecialchars functions in PHP before ...

CVSS2: 6.4
6%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-5653

The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by executing objects with the kill bit set in the corresponding ActiveX control Compatibility Flags, executing programs via a function in compatUI.dll, invoking wscript.shell via wscript.exe, invoking Scripting.FileSystemObject via wshom.ocx, and adding users via a function in shgina.dll, related to the com_load_typelib function.

CVSS2: 9.3
3%
Низкий
больше 18 лет назад

Уязвимостей на страницу