Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4 010

Количество 4 010

redhat логотип

CVE-2006-1494

больше 20 лет назад

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.

EPSS: Низкий
nvd логотип

CVE-2006-1494

больше 20 лет назад

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2006-1494

больше 20 лет назад

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 all ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2006-1490

больше 20 лет назад

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2006-1490

больше 20 лет назад

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

EPSS: Средний
nvd логотип

CVE-2006-1490

больше 20 лет назад

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2006-1490

больше 20 лет назад

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions o ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2006-1017

больше 20 лет назад

The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2006-1017

больше 20 лет назад

The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2006-1015

больше 20 лет назад

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 6.4
EPSS: Средний
nvd логотип

CVE-2006-1015

больше 20 лет назад

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 6.4
EPSS: Средний
debian логотип

CVE-2006-1015

больше 20 лет назад

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x appl ...

CVSS2: 6.4
EPSS: Средний
ubuntu логотип

CVE-2006-1014

больше 20 лет назад

Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 3.2
EPSS: Низкий
nvd логотип

CVE-2006-1014

больше 20 лет назад

Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 3.2
EPSS: Низкий
debian логотип

CVE-2006-1014

больше 20 лет назад

Argument injection vulnerability in certain PHP 4.x and 5.x applicatio ...

CVSS2: 3.2
EPSS: Низкий
ubuntu логотип

CVE-2006-0996

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2006-0996

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.

EPSS: Средний
nvd логотип

CVE-2006-0996

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2006-0996

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5. ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2006-0208

больше 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.

CVSS2: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2006-1494

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.

6%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1494

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.

CVSS2: 2.6
6%
Низкий
больше 20 лет назад
debian логотип
CVE-2006-1494

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 all ...

CVSS2: 2.6
6%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1490

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

CVSS2: 5
21%
Средний
больше 20 лет назад
redhat логотип
CVE-2006-1490

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

21%
Средний
больше 20 лет назад
nvd логотип
CVE-2006-1490

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

CVSS2: 5
21%
Средний
больше 20 лет назад
debian логотип
CVE-2006-1490

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions o ...

CVSS2: 5
21%
Средний
больше 20 лет назад
ubuntu логотип
CVE-2006-1017

The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.

CVSS2: 9.3
3%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1017

The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.

CVSS2: 9.3
3%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1015

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 6.4
12%
Средний
больше 20 лет назад
nvd логотип
CVE-2006-1015

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 6.4
12%
Средний
больше 20 лет назад
debian логотип
CVE-2006-1015

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x appl ...

CVSS2: 6.4
12%
Средний
больше 20 лет назад
ubuntu логотип
CVE-2006-1014

Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 3.2
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1014

Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 3.2
1%
Низкий
больше 20 лет назад
debian логотип
CVE-2006-1014

Argument injection vulnerability in certain PHP 4.x and 5.x applicatio ...

CVSS2: 3.2
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-0996

Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.

CVSS2: 4.3
11%
Средний
больше 20 лет назад
redhat логотип
CVE-2006-0996

Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.

11%
Средний
больше 20 лет назад
nvd логотип
CVE-2006-0996

Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.

CVSS2: 4.3
11%
Средний
больше 20 лет назад
debian логотип
CVE-2006-0996

Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5. ...

CVSS2: 4.3
11%
Средний
больше 20 лет назад
ubuntu логотип
CVE-2006-0208

Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.

CVSS2: 2.6
4%
Низкий
больше 20 лет назад

Уязвимостей на страницу