- EPSS 1.83%
- Veröffentlicht 12.03.2001 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:53:40
PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.
- EPSS 1.61%
- Veröffentlicht 12.01.2001 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:56:10
The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.
- EPSS 20.63%
- Veröffentlicht 19.12.2000 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:52:52
PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.
- EPSS 2.75%
- Veröffentlicht 14.11.2000 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:52:37
The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables.
- EPSS 10.92%
- Veröffentlicht 04.01.2000 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:50:55
PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.
CVE-1999-0068
- EPSS 7.03%
- Veröffentlicht 19.10.1997 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:47:30
CGI PHP mylog script allows an attacker to read any file on the target server.
- EPSS 6.12%
- Veröffentlicht 01.08.1997 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:47:58
php.cgi allows attackers to read any file on the system.
CVE-1999-0058
- EPSS 1.8%
- Veröffentlicht 17.04.1997 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:47:28
Buffer overflow in PHP cgi program, php.cgi allows shell access.