Php

Php

714 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 20.11.2007 18:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

PHP before 5.2.5 allows local users to bypass protection mechanisms configured through php_admin_value or php_admin_flag in httpd.conf by using ini_set to modify arbitrary configuration variables, a different issue than CVE-2006-4625.

  • EPSS 3.04%
  • Veröffentlicht 23.10.2007 21:47:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by executing objects with the kill b...

  • EPSS 3.37%
  • Veröffentlicht 14.10.2007 18:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by reading arbitrary f...

  • EPSS 0.32%
  • Veröffentlicht 12.10.2007 23:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The disable_functions feature in PHP 4 and 5 allows attackers to bypass intended restrictions by using an alias, as demonstrated by using ini_alter when ini_set is disabled.

  • EPSS 0.3%
  • Veröffentlicht 27.09.2007 19:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

SimpNews 2.41.03 on Windows, when PHP before 5.0.0 is used, allows remote attackers to obtain sensitive information via an certain link_date parameter to events.php, which reveals the path in an error message due to an unsupported argument type for t...

  • EPSS 0.61%
  • Veröffentlicht 14.09.2007 01:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The MySQL extension in PHP 5.2.4 and earlier allows remote attackers to bypass safe_mode and open_basedir restrictions via the MySQL (1) LOAD_FILE, (2) INTO DUMPFILE, and (3) INTO OUTFILE functions, a different issue than CVE-2007-3997.

  • EPSS 2.02%
  • Veröffentlicht 14.09.2007 00:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The dl function in PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in the library parameter. NOTE: there are limited usage scenarios under which this would be a vulnerabilit...

  • EPSS 1.59%
  • Veröffentlicht 12.09.2007 20:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the out_charset parameter to the iconv function; or a long string in the charset parameter to the (2) iconv_mime_decode...

  • EPSS 0.31%
  • Veröffentlicht 12.09.2007 01:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Directory traversal vulnerability in PHP 5.2.4 and earlier allows attackers to bypass open_basedir restrictions and possibly execute arbitrary code via a .. (dot dot) in the dl function.

Exploit
  • EPSS 3.28%
  • Veröffentlicht 10.09.2007 21:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

PHP before 5.2.3 allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the pattern parameter to the glob function; or (2) a long string in the string parameter to the fnmatch function, accompanie...