Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 9.73%
  • Veröffentlicht 30.06.2001 04:00:00
  • Zuletzt bearbeitet 16.06.2026 21:55:53

PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.

  • EPSS 1.83%
  • Veröffentlicht 12.03.2001 05:00:00
  • Zuletzt bearbeitet 16.06.2026 21:53:40

PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.

  • EPSS 1.61%
  • Veröffentlicht 12.01.2001 05:00:00
  • Zuletzt bearbeitet 16.06.2026 21:56:10

The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.

Exploit
  • EPSS 20.63%
  • Veröffentlicht 19.12.2000 05:00:00
  • Zuletzt bearbeitet 23.09.2026 09:10:01

PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.

Exploit
  • EPSS 2.75%
  • Veröffentlicht 14.11.2000 05:00:00
  • Zuletzt bearbeitet 16.06.2026 21:52:37

The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables.

  • EPSS 10.92%
  • Veröffentlicht 04.01.2000 05:00:00
  • Zuletzt bearbeitet 16.06.2026 21:50:55

PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.

  • EPSS 7.03%
  • Veröffentlicht 19.10.1997 04:00:00
  • Zuletzt bearbeitet 16.06.2026 21:47:30

CGI PHP mylog script allows an attacker to read any file on the target server.

  • EPSS 6.12%
  • Veröffentlicht 01.08.1997 04:00:00
  • Zuletzt bearbeitet 16.06.2026 21:47:58

php.cgi allows attackers to read any file on the system.

  • EPSS 1.8%
  • Veröffentlicht 17.04.1997 04:00:00
  • Zuletzt bearbeitet 16.06.2026 21:47:28

Buffer overflow in PHP cgi program, php.cgi allows shell access.