Show filters
412 Total Results
Displaying 11-20 of 412
Sort by:
Attacker Value
Unknown

CVE-2018-19784

Disclosure Date: December 01, 2018 (last updated November 27, 2024)
The str_rot_pass function in vendor/atholn1600/php-proxy/src/helpers.php in PHP-Proxy 5.1.0 uses weak cryptography, which makes it easier for attackers to calculate the authorization data needed for local file inclusion.
0
Attacker Value
Unknown

CVE-2018-19340

Disclosure Date: November 17, 2018 (last updated November 27, 2024)
Guriddo Form PHP 5.3 has XSS via the demos/jqform/defaultnodb/default.php OrderID, ShipName, ShipAddress, ShipCity, ShipPostalCode, ShipCountry, Freight, or details parameter.
0
Attacker Value
Unknown

CVE-2018-19246

Disclosure Date: November 13, 2018 (last updated November 27, 2024)
PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users who lack shell access to their web server) is used. This occurs because the aeb067ca0aa9a3193dce3a7264c90187 app_key value from the default config.php is in place, and this value can be easily used to calculate the authorization data needed for local file inclusion.
0
Attacker Value
Unknown

CVE-2018-18530

Disclosure Date: October 19, 2018 (last updated November 27, 2024)
ThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mishandles the aggregate variable. NOTE: a backquote character is required in the attack URI.
0
Attacker Value
Unknown

CVE-2018-17566

Disclosure Date: September 26, 2018 (last updated November 27, 2024)
In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's request.
0
Attacker Value
Unknown

CVE-2016-4473

Disclosure Date: June 08, 2017 (last updated November 26, 2024)
/ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as part of an incomplete fix to CVE-2015-6833.
0
Attacker Value
Unknown

CVE-2017-9067

Disclosure Date: May 18, 2017 (last updated November 26, 2024)
In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.
0
Attacker Value
Unknown

CVE-2017-7204

Disclosure Date: March 21, 2017 (last updated November 26, 2024)
A Cross-Site Scripting (XSS) was discovered in imdbphp 5.1.1. The vulnerability exists due to insufficient filtration of user-supplied data (name) passed to the "imdbphp-master/demo/search.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
0
Attacker Value
Unknown

CVE-2016-7478

Disclosure Date: January 11, 2017 (last updated November 25, 2024)
Zend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (infinite loop) via a crafted Exception object in serialized data, a related issue to CVE-2015-8876.
0
Attacker Value
Unknown

CVE-2014-9912

Disclosure Date: January 04, 2017 (last updated November 25, 2024)
The get_icu_disp_value_src_php function in ext/intl/locale/locale_methods.c in PHP before 5.3.29, 5.4.x before 5.4.30, and 5.5.x before 5.5.14 does not properly restrict calls to the ICU uresbund.cpp component, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a locale_get_display_name call with a long first argument.
0