CVE-2007-5900
- EPSS 0.07%
- Veröffentlicht 20.11.2007 18:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PHP before 5.2.5 allows local users to bypass protection mechanisms configured through php_admin_value or php_admin_flag in httpd.conf by using ini_set to modify arbitrary configuration variables, a different issue than CVE-2006-4625.
CVE-2007-5653
- EPSS 3.04%
- Veröffentlicht 23.10.2007 21:47:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by executing objects with the kill b...
CVE-2007-5447
- EPSS 3.37%
- Veröffentlicht 14.10.2007 18:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by reading arbitrary f...
CVE-2007-5424
- EPSS 0.32%
- Veröffentlicht 12.10.2007 23:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The disable_functions feature in PHP 4 and 5 allows attackers to bypass intended restrictions by using an alias, as demonstrated by using ini_alter when ini_set is disabled.
- EPSS 0.3%
- Veröffentlicht 27.09.2007 19:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SimpNews 2.41.03 on Windows, when PHP before 5.0.0 is used, allows remote attackers to obtain sensitive information via an certain link_date parameter to events.php, which reveals the path in an error message due to an unsupported argument type for t...
CVE-2007-4889
- EPSS 0.61%
- Veröffentlicht 14.09.2007 01:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The MySQL extension in PHP 5.2.4 and earlier allows remote attackers to bypass safe_mode and open_basedir restrictions via the MySQL (1) LOAD_FILE, (2) INTO DUMPFILE, and (3) INTO OUTFILE functions, a different issue than CVE-2007-3997.
CVE-2007-4887
- EPSS 2.02%
- Veröffentlicht 14.09.2007 00:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The dl function in PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in the library parameter. NOTE: there are limited usage scenarios under which this would be a vulnerabilit...
- EPSS 1.59%
- Veröffentlicht 12.09.2007 20:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the out_charset parameter to the iconv function; or a long string in the charset parameter to the (2) iconv_mime_decode...
CVE-2007-4825
- EPSS 0.31%
- Veröffentlicht 12.09.2007 01:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Directory traversal vulnerability in PHP 5.2.4 and earlier allows attackers to bypass open_basedir restrictions and possibly execute arbitrary code via a .. (dot dot) in the dl function.
- EPSS 3.28%
- Veröffentlicht 10.09.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PHP before 5.2.3 allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the pattern parameter to the glob function; or (2) a long string in the string parameter to the fnmatch function, accompanie...