Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 863

Количество 3 863

ubuntu логотип

CVE-2006-1608

больше 19 лет назад

The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass safe mode and read arbitrary files via a source argument containing a compress.zlib:// URI.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2006-1608

больше 19 лет назад

The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass safe mode and read arbitrary files via a source argument containing a compress.zlib:// URI.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2006-1608

больше 19 лет назад

The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2006-1549

больше 19 лет назад

PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function. NOTE: it has been reported by a reliable third party that some later versions are also affected.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2006-1549

больше 19 лет назад

PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function. NOTE: it has been reported by a reliable third party that some later versions are also affected.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2006-1549

больше 19 лет назад

PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2006-1494

больше 19 лет назад

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2006-1494

больше 19 лет назад

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.

EPSS: Низкий
nvd логотип

CVE-2006-1494

больше 19 лет назад

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2006-1494

больше 19 лет назад

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 all ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2006-1490

больше 19 лет назад

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2006-1490

больше 19 лет назад

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

EPSS: Средний
nvd логотип

CVE-2006-1490

больше 19 лет назад

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2006-1490

больше 19 лет назад

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions o ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2006-1017

больше 19 лет назад

The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2006-1017

больше 19 лет назад

The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2006-1015

больше 19 лет назад

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2006-1015

больше 19 лет назад

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2006-1015

больше 19 лет назад

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x appl ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2006-1014

больше 19 лет назад

Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 3.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2006-1608

The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass safe mode and read arbitrary files via a source argument containing a compress.zlib:// URI.

CVSS2: 2.1
0%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-1608

The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass safe mode and read arbitrary files via a source argument containing a compress.zlib:// URI.

CVSS2: 2.1
0%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-1608

The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users ...

CVSS2: 2.1
0%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-1549

PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function. NOTE: it has been reported by a reliable third party that some later versions are also affected.

CVSS2: 2.1
0%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-1549

PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function. NOTE: it has been reported by a reliable third party that some later versions are also affected.

CVSS2: 2.1
0%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-1549

PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation ...

CVSS2: 2.1
0%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-1494

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.

CVSS2: 2.6
4%
Низкий
больше 19 лет назад
redhat логотип
CVE-2006-1494

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.

4%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-1494

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.

CVSS2: 2.6
4%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-1494

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 all ...

CVSS2: 2.6
4%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-1490

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

CVSS2: 5
34%
Средний
больше 19 лет назад
redhat логотип
CVE-2006-1490

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

34%
Средний
больше 19 лет назад
nvd логотип
CVE-2006-1490

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

CVSS2: 5
34%
Средний
больше 19 лет назад
debian логотип
CVE-2006-1490

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions o ...

CVSS2: 5
34%
Средний
больше 19 лет назад
ubuntu логотип
CVE-2006-1017

The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.

CVSS2: 9.3
5%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-1017

The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.

CVSS2: 9.3
5%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-1015

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 6.4
4%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-1015

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 6.4
4%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-1015

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x appl ...

CVSS2: 6.4
4%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-1014

Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 3.2
2%
Низкий
больше 19 лет назад

Уязвимостей на страницу