Show filters
171 Total Results
Displaying 101-110 of 171
Sort by:
Attacker Value
Unknown
CVE-2007-0910
Disclosure Date: February 13, 2007 (last updated October 04, 2023)
Unspecified vulnerability in PHP before 5.2.1 allows attackers to "clobber" certain super-global variables via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-0908
Disclosure Date: February 13, 2007 (last updated October 04, 2023)
The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a numerical key, which allows context-dependent attackers to read stack memory via a wddxPacket element that contains a variable with a string name before a numerical variable.
0
Attacker Value
Unknown
CVE-2007-0905
Disclosure Date: February 13, 2007 (last updated October 04, 2023)
PHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension. NOTE: it is possible that this issue is a duplicate of CVE-2006-6383.
0
Attacker Value
Unknown
CVE-2007-0455
Disclosure Date: January 30, 2007 (last updated October 04, 2023)
Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.
0
Attacker Value
Unknown
CVE-2006-6186
Disclosure Date: December 01, 2006 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in enomphp 4.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter to (1) config.php, (2) ranklv_inside.php, (3) rankml_inside.php, and (4) admin/Restore/config.php.
0
Attacker Value
Unknown
CVE-2006-6039
Disclosure Date: November 22, 2006 (last updated October 04, 2023)
SQL injection vulnerability in matchdetail.php in Powie's PHP MatchMaker 4.05 and earlier allows remote attackers to execute arbitrary SQL commands via the edit parameter.
0
Attacker Value
Unknown
CVE-2006-4812
Disclosure Date: October 10, 2006 (last updated October 04, 2023)
Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with a large value for the number of array elements, which triggers the overflow in the Zend Engine ecalloc function (Zend/zend_alloc.c).
0
Attacker Value
Unknown
CVE-2006-5178
Disclosure Date: October 10, 2006 (last updated October 04, 2023)
Race condition in the symlink function in PHP 5.1.6 and earlier allows local users to bypass the open_basedir restriction by using a combination of symlink, mkdir, and unlink functions to change the file path after the open_basedir check and before the file is opened by the underlying system, as demonstrated by symlinking a symlink into a subdirectory, to point to a parent directory via .. (dot dot) sequences, and then unlinking the resulting symlink.
0
Attacker Value
Unknown
CVE-2006-4828
Disclosure Date: September 15, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in zipndownload.php in PhotoPost 4.0 through 4.6 allows remote attackers to execute arbitrary PHP code via a URL in the PP_PATH parameter.
0
Attacker Value
Unknown
CVE-2006-4625
Disclosure Date: September 12, 2006 (last updated October 04, 2023)
PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.
0