Количество 11
Количество 11

BDU:2022-02533
Уязвимость интерпретатора языка программирования PHP, связана с ошибкой при обработке при обработке путей к файлам с символом \x00, позволяющая нарушителю получить несанкционированный доступ к файлам или каталогам

CVE-2015-4025
PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and access files or directories with unexpected names via a crafted argument to (1) set_include_path, (2) tempnam, (3) rmdir, or (4) readlink. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.

CVE-2015-4025
PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and access files or directories with unexpected names via a crafted argument to (1) set_include_path, (2) tempnam, (3) rmdir, or (4) readlink. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.

CVE-2015-4025
PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and access files or directories with unexpected names via a crafted argument to (1) set_include_path, (2) tempnam, (3) rmdir, or (4) readlink. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.
CVE-2015-4025
PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncat ...
GHSA-8472-42qg-pj78
PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and access files or directories with unexpected names via a crafted argument to (1) set_include_path, (2) tempnam, (3) rmdir, or (4) readlink. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.

openSUSE-SU-2017:3329-1
Security update for php5

SUSE-SU-2017:3277-1
Security update for php5
ELSA-2015-1219
ELSA-2015-1219: php54-php security update (MODERATE)
ELSA-2015-1186
ELSA-2015-1186: php55-php security update (IMPORTANT)
ELSA-2015-1135
ELSA-2015-1135: php security and bug fix update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | BDU:2022-02533 Уязвимость интерпретатора языка программирования PHP, связана с ошибкой при обработке при обработке путей к файлам с символом \x00, позволяющая нарушителю получить несанкционированный доступ к файлам или каталогам | CVSS3: 6.5 | 9% Низкий | около 10 лет назад |
![]() | CVE-2015-4025 PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and access files or directories with unexpected names via a crafted argument to (1) set_include_path, (2) tempnam, (3) rmdir, or (4) readlink. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243. | CVSS2: 7.5 | 9% Низкий | около 10 лет назад |
![]() | CVE-2015-4025 PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and access files or directories with unexpected names via a crafted argument to (1) set_include_path, (2) tempnam, (3) rmdir, or (4) readlink. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243. | CVSS2: 4 | 9% Низкий | около 10 лет назад |
![]() | CVE-2015-4025 PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and access files or directories with unexpected names via a crafted argument to (1) set_include_path, (2) tempnam, (3) rmdir, or (4) readlink. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243. | CVSS2: 7.5 | 9% Низкий | около 10 лет назад |
CVE-2015-4025 PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncat ... | CVSS2: 7.5 | 9% Низкий | около 10 лет назад | |
GHSA-8472-42qg-pj78 PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and access files or directories with unexpected names via a crafted argument to (1) set_include_path, (2) tempnam, (3) rmdir, or (4) readlink. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243. | 9% Низкий | около 3 лет назад | ||
![]() | openSUSE-SU-2017:3329-1 Security update for php5 | больше 7 лет назад | ||
![]() | SUSE-SU-2017:3277-1 Security update for php5 | больше 7 лет назад | ||
ELSA-2015-1219 ELSA-2015-1219: php54-php security update (MODERATE) | больше 9 лет назад | |||
ELSA-2015-1186 ELSA-2015-1186: php55-php security update (IMPORTANT) | больше 9 лет назад | |||
ELSA-2015-1135 ELSA-2015-1135: php security and bug fix update (IMPORTANT) | почти 10 лет назад |
Уязвимостей на страницу