- EPSS 5.58%
- Veröffentlicht 25.01.2008 01:00:00
- Zuletzt bearbeitet 16.06.2026 22:44:54
curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vuln...
CVE-2008-0145
- EPSS 2.31%
- Veröffentlicht 08.01.2008 19:46:00
- Zuletzt bearbeitet 16.06.2026 22:49:01
Unspecified vulnerability in glob in PHP before 4.4.8, when open_basedir is enabled, has unknown impact and attack vectors. NOTE: this issue reportedly exists because of a regression related to CVE-2007-4663.
CVE-2007-5899
- EPSS 3.39%
- Veröffentlicht 20.11.2007 19:46:00
- Zuletzt bearbeitet 16.06.2026 22:46:59
The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as ...
CVE-2007-6039
- EPSS 1.03%
- Veröffentlicht 20.11.2007 19:46:00
- Zuletzt bearbeitet 16.06.2026 22:47:18
PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in (1) the domain parameter to the dgettext function, the message parameter to the (2) dcgettext or (3) gettext function, the ...
CVE-2007-5898
- EPSS 2.79%
- Veröffentlicht 20.11.2007 18:46:00
- Zuletzt bearbeitet 16.06.2026 22:46:59
The (1) htmlentities and (2) htmlspecialchars functions in PHP before 5.2.5 accept partial multibyte sequences, which has unknown impact and attack vectors, a different issue than CVE-2006-5465.
CVE-2007-5900
- EPSS 0.34%
- Veröffentlicht 20.11.2007 18:46:00
- Zuletzt bearbeitet 16.06.2026 22:46:59
PHP before 5.2.5 allows local users to bypass protection mechanisms configured through php_admin_value or php_admin_flag in httpd.conf by using ini_set to modify arbitrary configuration variables, a different issue than CVE-2006-4625.
CVE-2007-5653
- EPSS 4.82%
- Veröffentlicht 23.10.2007 21:47:00
- Zuletzt bearbeitet 16.06.2026 22:46:34
The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by executing objects with the kill b...
CVE-2007-5447
- EPSS 4.58%
- Veröffentlicht 14.10.2007 18:17:00
- Zuletzt bearbeitet 16.06.2026 22:46:10
ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by reading arbitrary f...
CVE-2007-5424
- EPSS 1.69%
- Veröffentlicht 12.10.2007 23:17:00
- Zuletzt bearbeitet 16.06.2026 22:46:06
The disable_functions feature in PHP 4 and 5 allows attackers to bypass intended restrictions by using an alias, as demonstrated by using ini_alter when ini_set is disabled.
- EPSS 1.24%
- Veröffentlicht 27.09.2007 19:17:00
- Zuletzt bearbeitet 16.06.2026 22:45:29
SimpNews 2.41.03 on Windows, when PHP before 5.0.0 is used, allows remote attackers to obtain sensitive information via an certain link_date parameter to events.php, which reveals the path in an error message due to an unsupported argument type for t...