Количество 18
Количество 18
BDU:2016-01374
Уязвимость интерпретатора PHP, позволяющая нарушителю читать произвольные файлы или записывать в них
CVE-2015-3411
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load method, (2) the xmlwriter_open_uri function, (3) the finfo_file function, or (4) the hash_hmac_file function, as demonstrated by a filename\0.xml attack that bypasses an intended configuration in which client users may read only .xml files.
CVE-2015-3411
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load method, (2) the xmlwriter_open_uri function, (3) the finfo_file function, or (4) the hash_hmac_file function, as demonstrated by a filename\0.xml attack that bypasses an intended configuration in which client users may read only .xml files.
CVE-2015-3411
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load method, (2) the xmlwriter_open_uri function, (3) the finfo_file function, or (4) the hash_hmac_file function, as demonstrated by a filename\0.xml attack that bypasses an intended configuration in which client users may read only .xml files.
CVE-2015-3411
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does no ...
GHSA-4gf4-5fpq-6cwc
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load method, (2) the xmlwriter_open_uri function, (3) the finfo_file function, or (4) the hash_hmac_file function, as demonstrated by a filename\0.xml attack that bypasses an intended configuration in which client users may read only .xml files.
SUSE-SU-2023:0072-1
Security update for php74
SUSE-SU-2015:1253-2
Security update for php5
SUSE-SU-2015:1253-1
Security update for php5
ELSA-2015-1186
ELSA-2015-1186: php55-php security update (IMPORTANT)
ELSA-2015-1218
ELSA-2015-1218: php security update (MODERATE)
ELSA-2015-1066
ELSA-2015-1066: php54 security and bug fix update (IMPORTANT)
ELSA-2015-1135
ELSA-2015-1135: php security and bug fix update (IMPORTANT)
SUSE-SU-2015:1265-1
Security update for php53
SUSE-SU-2015:1018-1
Security update for php53
SUSE-SU-2015:0436-1
Security update for php53
SUSE-SU-2015:0370-1
Security update for php53
SUSE-SU-2016:1638-1
Security update for php53
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2016-01374 Уязвимость интерпретатора PHP, позволяющая нарушителю читать произвольные файлы или записывать в них | CVSS2: 6.4 | 0% Низкий | больше 9 лет назад | |
CVE-2015-3411 PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load method, (2) the xmlwriter_open_uri function, (3) the finfo_file function, or (4) the hash_hmac_file function, as demonstrated by a filename\0.xml attack that bypasses an intended configuration in which client users may read only .xml files. | CVSS3: 6.5 | 0% Низкий | больше 9 лет назад | |
CVE-2015-3411 PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load method, (2) the xmlwriter_open_uri function, (3) the finfo_file function, or (4) the hash_hmac_file function, as demonstrated by a filename\0.xml attack that bypasses an intended configuration in which client users may read only .xml files. | CVSS2: 4 | 0% Низкий | больше 10 лет назад | |
CVE-2015-3411 PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load method, (2) the xmlwriter_open_uri function, (3) the finfo_file function, or (4) the hash_hmac_file function, as demonstrated by a filename\0.xml attack that bypasses an intended configuration in which client users may read only .xml files. | CVSS3: 6.5 | 0% Низкий | больше 9 лет назад | |
CVE-2015-3411 PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does no ... | CVSS3: 6.5 | 0% Низкий | больше 9 лет назад | |
GHSA-4gf4-5fpq-6cwc PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load method, (2) the xmlwriter_open_uri function, (3) the finfo_file function, or (4) the hash_hmac_file function, as demonstrated by a filename\0.xml attack that bypasses an intended configuration in which client users may read only .xml files. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
SUSE-SU-2023:0072-1 Security update for php74 | почти 3 года назад | |||
SUSE-SU-2015:1253-2 Security update for php5 | больше 10 лет назад | |||
SUSE-SU-2015:1253-1 Security update for php5 | больше 10 лет назад | |||
ELSA-2015-1186 ELSA-2015-1186: php55-php security update (IMPORTANT) | почти 10 лет назад | |||
ELSA-2015-1218 ELSA-2015-1218: php security update (MODERATE) | больше 10 лет назад | |||
ELSA-2015-1066 ELSA-2015-1066: php54 security and bug fix update (IMPORTANT) | почти 10 лет назад | |||
ELSA-2015-1135 ELSA-2015-1135: php security and bug fix update (IMPORTANT) | больше 10 лет назад | |||
SUSE-SU-2015:1265-1 Security update for php53 | около 11 лет назад | |||
SUSE-SU-2015:1018-1 Security update for php53 | около 11 лет назад | |||
SUSE-SU-2015:0436-1 Security update for php53 | около 11 лет назад | |||
SUSE-SU-2015:0370-1 Security update for php53 | около 11 лет назад | |||
SUSE-SU-2016:1638-1 Security update for php53 | больше 9 лет назад |
Уязвимостей на страницу