Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 863

Количество 3 863

nvd логотип

CVE-2006-1014

больше 19 лет назад

Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 3.2
EPSS: Низкий
debian логотип

CVE-2006-1014

больше 19 лет назад

Argument injection vulnerability in certain PHP 4.x and 5.x applicatio ...

CVSS2: 3.2
EPSS: Низкий
ubuntu логотип

CVE-2006-0996

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2006-0996

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.

EPSS: Средний
nvd логотип

CVE-2006-0996

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2006-0996

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5. ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2006-0208

больше 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2006-0208

больше 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.

EPSS: Низкий
nvd логотип

CVE-2006-0208

больше 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2006-0208

больше 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5 ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2006-0207

больше 19 лет назад

Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-0207

больше 19 лет назад

Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2006-0207

больше 19 лет назад

Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow re ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-0200

больше 19 лет назад

Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.

CVSS2: 9.3
EPSS: Средний
nvd логотип

CVE-2006-0200

больше 19 лет назад

Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.

CVSS2: 9.3
EPSS: Средний
debian логотип

CVE-2006-0200

больше 19 лет назад

Format string vulnerability in the error-reporting feature in the mysq ...

CVSS2: 9.3
EPSS: Средний
nvd логотип

CVE-2006-0097

больше 19 лет назад

Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long named pipe variable in the host argument to the mysql_connect function.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2006-0097

больше 19 лет назад

Stack-based buffer overflow in the create_named_pipe function in libmy ...

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2005-3883

больше 19 лет назад

CRLF injection vulnerability in the mb_send_mail function in PHP before 5.1.0 might allow remote attackers to inject arbitrary e-mail headers via line feeds (LF) in the "To" address argument.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2005-3883

почти 20 лет назад

CRLF injection vulnerability in the mb_send_mail function in PHP before 5.1.0 might allow remote attackers to inject arbitrary e-mail headers via line feeds (LF) in the "To" address argument.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2006-1014

Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 3.2
2%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-1014

Argument injection vulnerability in certain PHP 4.x and 5.x applicatio ...

CVSS2: 3.2
2%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-0996

Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.

CVSS2: 4.3
20%
Средний
больше 19 лет назад
redhat логотип
CVE-2006-0996

Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.

20%
Средний
больше 19 лет назад
nvd логотип
CVE-2006-0996

Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.

CVSS2: 4.3
20%
Средний
больше 19 лет назад
debian логотип
CVE-2006-0996

Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5. ...

CVSS2: 4.3
20%
Средний
больше 19 лет назад
ubuntu логотип
CVE-2006-0208

Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.

CVSS2: 2.6
3%
Низкий
больше 19 лет назад
redhat логотип
CVE-2006-0208

Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.

3%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-0208

Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.

CVSS2: 2.6
3%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-0208

Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5 ...

CVSS2: 2.6
3%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-0207

Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.

CVSS2: 5
6%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-0207

Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.

CVSS2: 5
6%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-0207

Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow re ...

CVSS2: 5
6%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-0200

Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.

CVSS2: 9.3
11%
Средний
больше 19 лет назад
nvd логотип
CVE-2006-0200

Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.

CVSS2: 9.3
11%
Средний
больше 19 лет назад
debian логотип
CVE-2006-0200

Format string vulnerability in the error-reporting feature in the mysq ...

CVSS2: 9.3
11%
Средний
больше 19 лет назад
nvd логотип
CVE-2006-0097

Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long named pipe variable in the host argument to the mysql_connect function.

CVSS2: 7.5
19%
Средний
больше 19 лет назад
debian логотип
CVE-2006-0097

Stack-based buffer overflow in the create_named_pipe function in libmy ...

CVSS2: 7.5
19%
Средний
больше 19 лет назад
ubuntu логотип
CVE-2005-3883

CRLF injection vulnerability in the mb_send_mail function in PHP before 5.1.0 might allow remote attackers to inject arbitrary e-mail headers via line feeds (LF) in the "To" address argument.

CVSS2: 5
2%
Низкий
больше 19 лет назад
redhat логотип
CVE-2005-3883

CRLF injection vulnerability in the mb_send_mail function in PHP before 5.1.0 might allow remote attackers to inject arbitrary e-mail headers via line feeds (LF) in the "To" address argument.

2%
Низкий
почти 20 лет назад

Уязвимостей на страницу