Количество 3 863
Количество 3 863

CVE-2002-2214
The php_if_imap_mime_header_decode function in the IMAP functionality in PHP before 4.2.2 allows remote attackers to cause a denial of service (crash) via an e-mail header with a long "To" header.
CVE-2002-2214
The php_if_imap_mime_header_decode function in the IMAP functionality ...

CVE-2002-1954
Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php.
CVE-2002-1954
Cross-site scripting (XSS) vulnerability in the phpinfo function in PH ...

CVE-2002-1783
CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_url_fopen is enabled, allows remote attackers to modify HTTP headers for outgoing requests by causing CRLF sequences to be injected into arguments that are passed to the (1) fopen or (2) file functions.
CVE-2002-1783
CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_ur ...

CVE-2002-1396
Heap-based buffer overflow in the wordwrap function in PHP after 4.1.2 and before 4.3.0 may allow attackers to cause a denial of service or execute arbitrary code.

CVE-2002-1396
Heap-based buffer overflow in the wordwrap function in PHP after 4.1.2 and before 4.3.0 may allow attackers to cause a denial of service or execute arbitrary code.
CVE-2002-1396
Heap-based buffer overflow in the wordwrap function in PHP after 4.1.2 ...

CVE-2002-0986
The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy."

CVE-2002-0986
The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy."
CVE-2002-0986
The mail function in PHP 4.x to 4.2.2 does not filter ASCII control ch ...

CVE-2002-0717
PHP 4.2.0 and 4.2.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP POST request with certain arguments in a multipart/form-data form, which generates an error condition that is not properly handled and causes improper memory to be freed.
CVE-2002-0717
PHP 4.2.0 and 4.2.1 allows remote attackers to cause a denial of servi ...

CVE-2002-0484
move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system.

CVE-2002-0253
PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote attackers to obtain the physical path for an include file via a trailing slash in a request to a directly accessible PHP program, which modifies the base path, causes the include directive to fail, and produces an error message that contains the path.

CVE-2002-0229
Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.

CVE-2002-0121
PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.

CVE-2002-0081
Buffer overflows in (1) php_mime_split in PHP 4.1.0, 4.1.1, and 4.0.6 and earlier, and (2) php3_mime_split in PHP 3.0.x allows remote attackers to execute arbitrary code via a multipart/form-data HTTP POST request when file_uploads is enabled.

CVE-2002-0081
Buffer overflows in (1) php_mime_split in PHP 4.1.0, 4.1.1, and 4.0.6 and earlier, and (2) php3_mime_split in PHP 3.0.x allows remote attackers to execute arbitrary code via a multipart/form-data HTTP POST request when file_uploads is enabled.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2002-2214 The php_if_imap_mime_header_decode function in the IMAP functionality in PHP before 4.2.2 allows remote attackers to cause a denial of service (crash) via an e-mail header with a long "To" header. | CVSS2: 5 | 1% Низкий | больше 22 лет назад |
CVE-2002-2214 The php_if_imap_mime_header_decode function in the IMAP functionality ... | CVSS2: 5 | 1% Низкий | больше 22 лет назад | |
![]() | CVE-2002-1954 Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php. | CVSS2: 4.3 | 3% Низкий | больше 22 лет назад |
CVE-2002-1954 Cross-site scripting (XSS) vulnerability in the phpinfo function in PH ... | CVSS2: 4.3 | 3% Низкий | больше 22 лет назад | |
![]() | CVE-2002-1783 CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_url_fopen is enabled, allows remote attackers to modify HTTP headers for outgoing requests by causing CRLF sequences to be injected into arguments that are passed to the (1) fopen or (2) file functions. | CVSS2: 5 | 1% Низкий | больше 22 лет назад |
CVE-2002-1783 CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_ur ... | CVSS2: 5 | 1% Низкий | больше 22 лет назад | |
![]() | CVE-2002-1396 Heap-based buffer overflow in the wordwrap function in PHP after 4.1.2 and before 4.3.0 may allow attackers to cause a denial of service or execute arbitrary code. | 2% Низкий | больше 22 лет назад | |
![]() | CVE-2002-1396 Heap-based buffer overflow in the wordwrap function in PHP after 4.1.2 and before 4.3.0 may allow attackers to cause a denial of service or execute arbitrary code. | CVSS2: 7.5 | 2% Низкий | больше 22 лет назад |
CVE-2002-1396 Heap-based buffer overflow in the wordwrap function in PHP after 4.1.2 ... | CVSS2: 7.5 | 2% Низкий | больше 22 лет назад | |
![]() | CVE-2002-0986 The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy." | 6% Низкий | около 23 лет назад | |
![]() | CVE-2002-0986 The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy." | CVSS2: 5 | 6% Низкий | почти 23 года назад |
CVE-2002-0986 The mail function in PHP 4.x to 4.2.2 does not filter ASCII control ch ... | CVSS2: 5 | 6% Низкий | почти 23 года назад | |
![]() | CVE-2002-0717 PHP 4.2.0 and 4.2.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP POST request with certain arguments in a multipart/form-data form, which generates an error condition that is not properly handled and causes improper memory to be freed. | CVSS2: 7.5 | 5% Низкий | около 23 лет назад |
CVE-2002-0717 PHP 4.2.0 and 4.2.1 allows remote attackers to cause a denial of servi ... | CVSS2: 7.5 | 5% Низкий | около 23 лет назад | |
![]() | CVE-2002-0484 move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system. | CVSS2: 5 | 4% Низкий | около 23 лет назад |
![]() | CVE-2002-0253 PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote attackers to obtain the physical path for an include file via a trailing slash in a request to a directly accessible PHP program, which modifies the base path, causes the include directive to fail, and produces an error message that contains the path. | CVSS2: 5 | 1% Низкий | около 23 лет назад |
![]() | CVE-2002-0229 Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements. | CVSS2: 7.5 | 8% Низкий | больше 23 лет назад |
![]() | CVE-2002-0121 PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections. | CVSS2: 2.1 | 0% Низкий | больше 23 лет назад |
![]() | CVE-2002-0081 Buffer overflows in (1) php_mime_split in PHP 4.1.0, 4.1.1, and 4.0.6 and earlier, and (2) php3_mime_split in PHP 3.0.x allows remote attackers to execute arbitrary code via a multipart/form-data HTTP POST request when file_uploads is enabled. | 44% Средний | больше 23 лет назад | |
![]() | CVE-2002-0081 Buffer overflows in (1) php_mime_split in PHP 4.1.0, 4.1.1, and 4.0.6 and earlier, and (2) php3_mime_split in PHP 3.0.x allows remote attackers to execute arbitrary code via a multipart/form-data HTTP POST request when file_uploads is enabled. | CVSS2: 7.5 | 44% Средний | больше 23 лет назад |
Уязвимостей на страницу