Php

Php

711 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 89.96%
  • Veröffentlicht 11.05.2012 10:15:48
  • Zuletzt bearbeitet 11.04.2025 00:51:21

sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that contain a %3D sequence but no = (equals sign) character, which allows remote attackers to exec...

  • EPSS 79.57%
  • Veröffentlicht 11.05.2012 10:15:48
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.

  • EPSS 20.58%
  • Veröffentlicht 11.05.2012 10:15:48
  • Zuletzt bearbeitet 11.04.2025 00:51:21

php-wrapper.fcgi does not properly handle command-line arguments, which allows remote attackers to bypass a protection mechanism in PHP 5.3.12 and 5.4.2 and execute arbitrary code by leveraging improper interaction between the PHP sapi/cgi/cgi_main.c...

  • EPSS 11.07%
  • Veröffentlicht 11.05.2012 10:15:48
  • Zuletzt bearbeitet 11.04.2025 00:51:21

sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service ...

  • EPSS 9.13%
  • Veröffentlicht 14.02.2012 15:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) via a crafted application that uses a PDO driver for a fetch and then ca...

Exploit
  • EPSS 5.69%
  • Veröffentlicht 14.02.2012 15:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Memory leak in the timezone functionality in PHP before 5.3.9 allows remote attackers to cause a denial of service (memory consumption) by triggering many strtotime function calls, which are not properly handled by the php_date_parse_tzfile cache.

Exploit
  • EPSS 10.63%
  • Veröffentlicht 10.02.2012 20:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related...

Exploit
  • EPSS 30.62%
  • Veröffentlicht 06.02.2012 20:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. NOTE: this vulnerability e...

  • EPSS 1.59%
  • Veröffentlicht 02.02.2012 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

PHP before 5.3.9 has improper libxslt security settings, which allows remote attackers to create arbitrary files via a crafted XSLT stylesheet that uses the libxslt output extension.

Exploit
  • EPSS 4.35%
  • Veröffentlicht 18.01.2012 20:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The tidy_diagnose function in PHP 5.3.8 might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that attempts to perform Tidy::diagnose operations on invalid objec...