Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 866

Количество 3 866

debian логотип

CVE-2007-5898

почти 18 лет назад

The (1) htmlentities and (2) htmlspecialchars functions in PHP before ...

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2007-5653

почти 18 лет назад

The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by executing objects with the kill bit set in the corresponding ActiveX control Compatibility Flags, executing programs via a function in compatUI.dll, invoking wscript.shell via wscript.exe, invoking Scripting.FileSystemObject via wshom.ocx, and adding users via a function in shgina.dll, related to the com_load_typelib function.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2007-5653

почти 18 лет назад

The Component Object Model (COM) functions in PHP 5.x on Windows do no ...

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2007-5424

почти 18 лет назад

The disable_functions feature in PHP 4 and 5 allows attackers to bypass intended restrictions by using an alias, as demonstrated by using ini_alter when ini_set is disabled.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-5424

почти 18 лет назад

The disable_functions feature in PHP 4 and 5 allows attackers to bypass intended restrictions by using an alias, as demonstrated by using ini_alter when ini_set is disabled.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2007-5424

почти 18 лет назад

The disable_functions feature in PHP 4 and 5 allows attackers to bypas ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2007-4887

почти 18 лет назад

The dl function in PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in the library parameter. NOTE: there are limited usage scenarios under which this would be a vulnerability.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-4887

почти 18 лет назад

The dl function in PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in the library parameter. NOTE: there are limited usage scenarios under which this would be a vulnerability.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2007-4887

почти 18 лет назад

The dl function in PHP 5.2.4 and earlier allows context-dependent atta ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-4850

больше 17 лет назад

curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vulnerability than CVE-2006-2563.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2007-4850

больше 17 лет назад

curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vulnerability than CVE-2006-2563.

EPSS: Средний
nvd логотип

CVE-2007-4850

больше 17 лет назад

curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vulnerability than CVE-2006-2563.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2007-4850

больше 17 лет назад

curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5. ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2007-4840

почти 18 лет назад

PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the out_charset parameter to the iconv function; or a long string in the charset parameter to the (2) iconv_mime_decode_headers, (3) iconv_mime_decode, or (4) iconv_strlen function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-4840

почти 18 лет назад

PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the out_charset parameter to the iconv function; or a long string in the charset parameter to the (2) iconv_mime_decode_headers, (3) iconv_mime_decode, or (4) iconv_strlen function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2007-4840

почти 18 лет назад

PHP 5.2.4 and earlier allows context-dependent attackers to cause a de ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-4825

почти 18 лет назад

Directory traversal vulnerability in PHP 5.2.4 and earlier allows attackers to bypass open_basedir restrictions and possibly execute arbitrary code via a .. (dot dot) in the dl function.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-4825

почти 18 лет назад

Directory traversal vulnerability in PHP 5.2.4 and earlier allows attackers to bypass open_basedir restrictions and possibly execute arbitrary code via a .. (dot dot) in the dl function.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2007-4825

почти 18 лет назад

Directory traversal vulnerability in PHP 5.2.4 and earlier allows atta ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2007-4784

около 18 лет назад

The setlocale function in PHP before 5.2.4 allows context-dependent attackers to cause a denial of service (application crash) via a long string in the locale parameter. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless this issue can be demonstrated for code execution.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2007-5898

The (1) htmlentities and (2) htmlspecialchars functions in PHP before ...

CVSS2: 6.4
3%
Низкий
почти 18 лет назад
nvd логотип
CVE-2007-5653

The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by executing objects with the kill bit set in the corresponding ActiveX control Compatibility Flags, executing programs via a function in compatUI.dll, invoking wscript.shell via wscript.exe, invoking Scripting.FileSystemObject via wshom.ocx, and adding users via a function in shgina.dll, related to the com_load_typelib function.

CVSS2: 9.3
3%
Низкий
почти 18 лет назад
debian логотип
CVE-2007-5653

The Component Object Model (COM) functions in PHP 5.x on Windows do no ...

CVSS2: 9.3
3%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2007-5424

The disable_functions feature in PHP 4 and 5 allows attackers to bypass intended restrictions by using an alias, as demonstrated by using ini_alter when ini_set is disabled.

CVSS2: 7.5
0%
Низкий
почти 18 лет назад
nvd логотип
CVE-2007-5424

The disable_functions feature in PHP 4 and 5 allows attackers to bypass intended restrictions by using an alias, as demonstrated by using ini_alter when ini_set is disabled.

CVSS2: 7.5
0%
Низкий
почти 18 лет назад
debian логотип
CVE-2007-5424

The disable_functions feature in PHP 4 and 5 allows attackers to bypas ...

CVSS2: 7.5
0%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2007-4887

The dl function in PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in the library parameter. NOTE: there are limited usage scenarios under which this would be a vulnerability.

CVSS2: 4.3
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2007-4887

The dl function in PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in the library parameter. NOTE: there are limited usage scenarios under which this would be a vulnerability.

CVSS2: 4.3
2%
Низкий
почти 18 лет назад
debian логотип
CVE-2007-4887

The dl function in PHP 5.2.4 and earlier allows context-dependent atta ...

CVSS2: 4.3
2%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2007-4850

curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vulnerability than CVE-2006-2563.

CVSS2: 5
14%
Средний
больше 17 лет назад
redhat логотип
CVE-2007-4850

curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vulnerability than CVE-2006-2563.

14%
Средний
больше 17 лет назад
nvd логотип
CVE-2007-4850

curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vulnerability than CVE-2006-2563.

CVSS2: 5
14%
Средний
больше 17 лет назад
debian логотип
CVE-2007-4850

curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5. ...

CVSS2: 5
14%
Средний
больше 17 лет назад
ubuntu логотип
CVE-2007-4840

PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the out_charset parameter to the iconv function; or a long string in the charset parameter to the (2) iconv_mime_decode_headers, (3) iconv_mime_decode, or (4) iconv_strlen function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.

CVSS2: 5
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2007-4840

PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the out_charset parameter to the iconv function; or a long string in the charset parameter to the (2) iconv_mime_decode_headers, (3) iconv_mime_decode, or (4) iconv_strlen function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.

CVSS2: 5
1%
Низкий
почти 18 лет назад
debian логотип
CVE-2007-4840

PHP 5.2.4 and earlier allows context-dependent attackers to cause a de ...

CVSS2: 5
1%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2007-4825

Directory traversal vulnerability in PHP 5.2.4 and earlier allows attackers to bypass open_basedir restrictions and possibly execute arbitrary code via a .. (dot dot) in the dl function.

CVSS2: 7.5
0%
Низкий
почти 18 лет назад
nvd логотип
CVE-2007-4825

Directory traversal vulnerability in PHP 5.2.4 and earlier allows attackers to bypass open_basedir restrictions and possibly execute arbitrary code via a .. (dot dot) in the dl function.

CVSS2: 7.5
0%
Низкий
почти 18 лет назад
debian логотип
CVE-2007-4825

Directory traversal vulnerability in PHP 5.2.4 and earlier allows atta ...

CVSS2: 7.5
0%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2007-4784

The setlocale function in PHP before 5.2.4 allows context-dependent attackers to cause a denial of service (application crash) via a long string in the locale parameter. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless this issue can be demonstrated for code execution.

CVSS2: 5
1%
Низкий
около 18 лет назад

Уязвимостей на страницу