Phpids

Phpids

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.47%
  • Veröffentlicht 29.12.2011 04:15:05
  • Zuletzt bearbeitet 16.06.2026 23:35:47

PHPIDS before 0.7 does not properly implement Regular Expression Denial of Service (ReDoS) filters, which allows remote attackers to bypass rulesets and add PHP sequences to a file via unspecified vectors.

  • EPSS 1.23%
  • Veröffentlicht 24.09.2011 00:55:02
  • Zuletzt bearbeitet 16.06.2026 23:33:55

PHPIDS 0.6.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/IDS/VersionTest.php and certain other files.

  • EPSS 1.05%
  • Veröffentlicht 05.07.2007 20:30:00
  • Zuletzt bearbeitet 16.06.2026 22:42:19

PHPIDS before 20070703 does not properly handle use of the substr method in (1) document.location.search and (2) document.referrer; (3) certain use of document.location.hash; (4) certain "window[eval" and similar expressions; (5) certain Function exp...

  • EPSS 1.08%
  • Veröffentlicht 05.07.2007 20:30:00
  • Zuletzt bearbeitet 16.06.2026 22:42:19

PHPIDS before 20070703 does not properly handle (1) arithmetic expressions and (2) unclosed comments, which allows remote attackers to inject arbitrary web script.

  • EPSS 1.05%
  • Veröffentlicht 05.07.2007 20:30:00
  • Zuletzt bearbeitet 16.06.2026 22:42:19

PHPIDS before 20070703 does not properly handle setting the .text property of a SCRIPT element before its attachment to the DOM, which allows remote attackers to inject arbitrary web script.

  • EPSS 1.05%
  • Veröffentlicht 05.07.2007 20:30:00
  • Zuletzt bearbeitet 16.06.2026 22:42:19

PHPIDS does not properly handle certain code containing newlines, as demonstrated by a try/catch block within a loop, which allows user-assisted remote attackers to inject arbitrary web script.