Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4 010

Количество 4 010

nvd логотип

CVE-2002-1396

больше 23 лет назад

Heap-based buffer overflow in the wordwrap function in PHP after 4.1.2 and before 4.3.0 may allow attackers to cause a denial of service or execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2002-1396

больше 23 лет назад

Heap-based buffer overflow in the wordwrap function in PHP after 4.1.2 ...

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2002-0986

около 24 лет назад

The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy."

EPSS: Низкий
nvd логотип

CVE-2002-0986

почти 24 года назад

The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy."

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2002-0986

почти 24 года назад

The mail function in PHP 4.x to 4.2.2 does not filter ASCII control ch ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0717

около 24 лет назад

PHP 4.2.0 and 4.2.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP POST request with certain arguments in a multipart/form-data form, which generates an error condition that is not properly handled and causes improper memory to be freed.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2002-0717

около 24 лет назад

PHP 4.2.0 and 4.2.1 allows remote attackers to cause a denial of servi ...

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0484

около 24 лет назад

move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0253

больше 24 лет назад

PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote attackers to obtain the physical path for an include file via a trailing slash in a request to a directly accessible PHP program, which modifies the base path, causes the include directive to fail, and produces an error message that contains the path.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0229

больше 24 лет назад

Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0121

больше 24 лет назад

PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2002-0081

больше 24 лет назад

Buffer overflows in (1) php_mime_split in PHP 4.1.0, 4.1.1, and 4.0.6 and earlier, and (2) php3_mime_split in PHP 3.0.x allows remote attackers to execute arbitrary code via a multipart/form-data HTTP POST request when file_uploads is enabled.

EPSS: Средний
nvd логотип

CVE-2002-0081

больше 24 лет назад

Buffer overflows in (1) php_mime_split in PHP 4.1.0, 4.1.1, and 4.0.6 and earlier, and (2) php3_mime_split in PHP 3.0.x allows remote attackers to execute arbitrary code via a multipart/form-data HTTP POST request when file_uploads is enabled.

CVSS2: 7.5
EPSS: Средний
redhat логотип

CVE-2001-1385

больше 25 лет назад

The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.

EPSS: Низкий
nvd логотип

CVE-2001-1385

больше 25 лет назад

The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2001-1247

около 25 лет назад

PHP 4.0.4pl1 and 4.0.5 in safe mode allows remote attackers to read and write files owned by the web server UID by uploading a PHP script that uses the error_log function to access the files.

EPSS: Низкий
nvd логотип

CVE-2001-1247

почти 25 лет назад

PHP 4.0.4pl1 and 4.0.5 in safe mode allows remote attackers to read and write files owned by the web server UID by uploading a PHP script that uses the error_log function to access the files.

CVSS2: 6.4
EPSS: Низкий
redhat логотип

CVE-2001-1246

около 25 лет назад

PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.

EPSS: Низкий
nvd логотип

CVE-2001-1246

около 25 лет назад

PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2001-0108

больше 25 лет назад

PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-1396

Heap-based buffer overflow in the wordwrap function in PHP after 4.1.2 and before 4.3.0 may allow attackers to cause a denial of service or execute arbitrary code.

CVSS2: 7.5
4%
Низкий
больше 23 лет назад
debian логотип
CVE-2002-1396

Heap-based buffer overflow in the wordwrap function in PHP after 4.1.2 ...

CVSS2: 7.5
4%
Низкий
больше 23 лет назад
redhat логотип
CVE-2002-0986

The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy."

5%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0986

The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy."

CVSS2: 5
5%
Низкий
почти 24 года назад
debian логотип
CVE-2002-0986

The mail function in PHP 4.x to 4.2.2 does not filter ASCII control ch ...

CVSS2: 5
5%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0717

PHP 4.2.0 and 4.2.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP POST request with certain arguments in a multipart/form-data form, which generates an error condition that is not properly handled and causes improper memory to be freed.

CVSS2: 7.5
11%
Средний
около 24 лет назад
debian логотип
CVE-2002-0717

PHP 4.2.0 and 4.2.1 allows remote attackers to cause a denial of servi ...

CVSS2: 7.5
11%
Средний
около 24 лет назад
nvd логотип
CVE-2002-0484

move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system.

CVSS2: 5
10%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0253

PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote attackers to obtain the physical path for an include file via a trailing slash in a request to a directly accessible PHP program, which modifies the base path, causes the include directive to fail, and produces an error message that contains the path.

CVSS2: 5
5%
Низкий
больше 24 лет назад
nvd логотип
CVE-2002-0229

Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.

CVSS2: 7.5
10%
Низкий
больше 24 лет назад
nvd логотип
CVE-2002-0121

PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.

CVSS2: 2.1
1%
Низкий
больше 24 лет назад
redhat логотип
CVE-2002-0081

Buffer overflows in (1) php_mime_split in PHP 4.1.0, 4.1.1, and 4.0.6 and earlier, and (2) php3_mime_split in PHP 3.0.x allows remote attackers to execute arbitrary code via a multipart/form-data HTTP POST request when file_uploads is enabled.

24%
Средний
больше 24 лет назад
nvd логотип
CVE-2002-0081

Buffer overflows in (1) php_mime_split in PHP 4.1.0, 4.1.1, and 4.0.6 and earlier, and (2) php3_mime_split in PHP 3.0.x allows remote attackers to execute arbitrary code via a multipart/form-data HTTP POST request when file_uploads is enabled.

CVSS2: 7.5
24%
Средний
больше 24 лет назад
redhat логотип
CVE-2001-1385

The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.

2%
Низкий
больше 25 лет назад
nvd логотип
CVE-2001-1385

The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.

CVSS2: 5
2%
Низкий
больше 25 лет назад
redhat логотип
CVE-2001-1247

PHP 4.0.4pl1 and 4.0.5 in safe mode allows remote attackers to read and write files owned by the web server UID by uploading a PHP script that uses the error_log function to access the files.

9%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1247

PHP 4.0.4pl1 and 4.0.5 in safe mode allows remote attackers to read and write files owned by the web server UID by uploading a PHP script that uses the error_log function to access the files.

CVSS2: 6.4
9%
Низкий
почти 25 лет назад
redhat логотип
CVE-2001-1246

PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.

10%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1246

PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.

CVSS2: 7.5
10%
Низкий
около 25 лет назад
redhat логотип
CVE-2001-0108

PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.

2%
Низкий
больше 25 лет назад

Уязвимостей на страницу