Количество 17
Количество 17

CVE-2015-4026
The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote attackers to bypass intended extension restrictions and execute files with unexpected names via a crafted first argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.

CVE-2015-4026
The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote attackers to bypass intended extension restrictions and execute files with unexpected names via a crafted first argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.

CVE-2015-4026
The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote attackers to bypass intended extension restrictions and execute files with unexpected names via a crafted first argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.
CVE-2015-4026
The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.2 ...
GHSA-2xvw-fxc9-x223
The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote attackers to bypass intended extension restrictions and execute files with unexpected names via a crafted first argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.

BDU:2022-02534
Уязвимость реализация pcntl_exec интерпретатора языка программирования PHP, связанная с ошибкой при обработке при обработке путей к файлам с символом \x00, позволяющая нарушителю обойти существующие ограничения безопасности и выполнить произвольный код
ELSA-2015-1219
ELSA-2015-1219: php54-php security update (MODERATE)

SUSE-SU-2015:1253-2
Security update for php5

SUSE-SU-2015:1253-1
Security update for php5
ELSA-2015-1186
ELSA-2015-1186: php55-php security update (IMPORTANT)
ELSA-2015-1218
ELSA-2015-1218: php security update (MODERATE)
ELSA-2015-1135
ELSA-2015-1135: php security and bug fix update (IMPORTANT)

SUSE-SU-2015:1265-1
Security update for php53

SUSE-SU-2015:1018-1
Security update for php53

SUSE-SU-2015:0436-1
Security update for php53

SUSE-SU-2015:0370-1
Security update for php53

SUSE-SU-2016:1638-1
Security update for php53
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2015-4026 The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote attackers to bypass intended extension restrictions and execute files with unexpected names via a crafted first argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243. | CVSS2: 7.5 | 10% Средний | около 10 лет назад |
![]() | CVE-2015-4026 The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote attackers to bypass intended extension restrictions and execute files with unexpected names via a crafted first argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243. | CVSS2: 4 | 10% Средний | около 10 лет назад |
![]() | CVE-2015-4026 The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote attackers to bypass intended extension restrictions and execute files with unexpected names via a crafted first argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243. | CVSS2: 7.5 | 10% Средний | около 10 лет назад |
CVE-2015-4026 The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.2 ... | CVSS2: 7.5 | 10% Средний | около 10 лет назад | |
GHSA-2xvw-fxc9-x223 The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote attackers to bypass intended extension restrictions and execute files with unexpected names via a crafted first argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243. | 10% Средний | около 3 лет назад | ||
![]() | BDU:2022-02534 Уязвимость реализация pcntl_exec интерпретатора языка программирования PHP, связанная с ошибкой при обработке при обработке путей к файлам с символом \x00, позволяющая нарушителю обойти существующие ограничения безопасности и выполнить произвольный код | CVSS3: 6.5 | 10% Средний | около 10 лет назад |
ELSA-2015-1219 ELSA-2015-1219: php54-php security update (MODERATE) | больше 9 лет назад | |||
![]() | SUSE-SU-2015:1253-2 Security update for php5 | почти 10 лет назад | ||
![]() | SUSE-SU-2015:1253-1 Security update for php5 | почти 10 лет назад | ||
ELSA-2015-1186 ELSA-2015-1186: php55-php security update (IMPORTANT) | больше 9 лет назад | |||
ELSA-2015-1218 ELSA-2015-1218: php security update (MODERATE) | почти 10 лет назад | |||
ELSA-2015-1135 ELSA-2015-1135: php security and bug fix update (IMPORTANT) | почти 10 лет назад | |||
![]() | SUSE-SU-2015:1265-1 Security update for php53 | больше 10 лет назад | ||
![]() | SUSE-SU-2015:1018-1 Security update for php53 | больше 10 лет назад | ||
![]() | SUSE-SU-2015:0436-1 Security update for php53 | больше 10 лет назад | ||
![]() | SUSE-SU-2015:0370-1 Security update for php53 | больше 10 лет назад | ||
![]() | SUSE-SU-2016:1638-1 Security update for php53 | почти 9 лет назад |
Уязвимостей на страницу