Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 4.65%
  • Veröffentlicht 28.03.2007 00:19:00
  • Zuletzt bearbeitet 16.06.2026 22:38:10

The mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 truncates e-mail messages at the first ASCIIZ ('\0') byte, which might allow context-dependent attackers to prevent intended information from being delivered in e-mail messages. NO...

Exploit
  • EPSS 6.69%
  • Veröffentlicht 28.03.2007 00:19:00
  • Zuletzt bearbeitet 16.06.2026 22:38:10

CRLF injection vulnerability in the mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows remote attackers to inject arbitrary e-mail headers and possibly conduct spam attacks via a control character immediately following folding of...

Exploit
  • EPSS 9.02%
  • Veröffentlicht 27.03.2007 01:19:00
  • Zuletzt bearbeitet 16.06.2026 22:38:08

The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbit...

  • EPSS 9.23%
  • Veröffentlicht 27.03.2007 01:19:00
  • Zuletzt bearbeitet 16.06.2026 22:38:08

PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables, as demonstrated by calling se...

  • EPSS 1.98%
  • Veröffentlicht 27.03.2007 01:19:00
  • Zuletzt bearbeitet 16.06.2026 22:38:09

Buffer overflow in the confirm_phpdoc_compiled function in the phpDOC extension (PECL phpDOC) in PHP 5.2.1 allows context-dependent attackers to execute arbitrary code via a long argument string.

  • EPSS 0.44%
  • Veröffentlicht 27.03.2007 01:19:00
  • Zuletzt bearbeitet 16.06.2026 22:38:09

The readfile function in PHP 4.4.4, 5.1.6, and 5.2.1 allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files by referring to local files with a certain URL syntax instead of a pathname syntax, as demonstrated by a...

  • EPSS 7.63%
  • Veröffentlicht 27.03.2007 01:19:00
  • Zuletzt bearbeitet 16.06.2026 22:38:09

Double free vulnerability in the unserializer in PHP 4.4.5 and 4.4.6 allows context-dependent attackers to execute arbitrary code by overwriting variables pointing to (1) the GLOBALS array or (2) the session data in _SESSION. NOTE: this issue was in...

Exploit
  • EPSS 7.21%
  • Veröffentlicht 24.03.2007 00:19:00
  • Zuletzt bearbeitet 16.06.2026 22:38:01

PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a serialized data input string beginning with S:, which does not properly track the number of input bytes being processed.

Exploit
  • EPSS 7.92%
  • Veröffentlicht 21.03.2007 23:19:00
  • Zuletzt bearbeitet 16.06.2026 22:37:52

The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file function via a userspace (1) error or (2) stream handler, which can then be used to destroy and modify in...

  • EPSS 5.92%
  • Veröffentlicht 21.03.2007 23:19:00
  • Zuletzt bearbeitet 16.06.2026 22:37:52

The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting certain functions in the GD (ext/gd) extension and unspecified other extensions via a userspace error ...