Php

Php

711 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 6.49%
  • Published 05.05.2008 17:20:00
  • Last modified 09.04.2025 00:30:58

The escapeshellcmd API function in PHP before 5.2.6 has unknown impact and context-dependent attack vectors related to "incomplete multibyte chars."

Exploit
  • EPSS 2.37%
  • Published 27.03.2008 17:44:00
  • Last modified 09.04.2025 00:30:58

Integer overflow in PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service and possibly have unspecified other impact via a printf format parameter with a large width specifier, related to the php_sprintf_appendstring f...

Exploit
  • EPSS 10.15%
  • Published 25.01.2008 01:00:00
  • Last modified 09.04.2025 00:30:58

curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vuln...

Exploit
  • EPSS 0.47%
  • Published 08.01.2008 19:46:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in glob in PHP before 4.4.8, when open_basedir is enabled, has unknown impact and attack vectors. NOTE: this issue reportedly exists because of a regression related to CVE-2007-4663.

  • EPSS 1.86%
  • Published 20.11.2007 19:46:00
  • Last modified 09.04.2025 00:30:58

The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as ...

  • EPSS 0.34%
  • Published 20.11.2007 19:46:00
  • Last modified 09.04.2025 00:30:58

PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in (1) the domain parameter to the dgettext function, the message parameter to the (2) dcgettext or (3) gettext function, the ...

  • EPSS 3.81%
  • Published 20.11.2007 18:46:00
  • Last modified 09.04.2025 00:30:58

The (1) htmlentities and (2) htmlspecialchars functions in PHP before 5.2.5 accept partial multibyte sequences, which has unknown impact and attack vectors, a different issue than CVE-2006-5465.

  • EPSS 0.05%
  • Published 20.11.2007 18:46:00
  • Last modified 09.04.2025 00:30:58

PHP before 5.2.5 allows local users to bypass protection mechanisms configured through php_admin_value or php_admin_flag in httpd.conf by using ini_set to modify arbitrary configuration variables, a different issue than CVE-2006-4625.

  • EPSS 3.04%
  • Published 23.10.2007 21:47:00
  • Last modified 09.04.2025 00:30:58

The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by executing objects with the kill b...

  • EPSS 3.16%
  • Published 14.10.2007 18:17:00
  • Last modified 09.04.2025 00:30:58

ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by reading arbitrary f...