Show filters
117 Total Results
Displaying 111-117 of 117
Sort by:
Attacker Value
Unknown
CVE-2002-1783
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_url_fopen is enabled, allows remote attackers to modify HTTP headers for outgoing requests by causing CRLF sequences to be injected into arguments that are passed to the (1) fopen or (2) file functions.
0
Attacker Value
Unknown
CVE-2002-0986
Disclosure Date: September 24, 2002 (last updated February 22, 2025)
The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy."
0
Attacker Value
Unknown
CVE-2002-0484
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system.
0
Attacker Value
Unknown
CVE-2002-0253
Disclosure Date: May 29, 2002 (last updated February 22, 2025)
PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote attackers to obtain the physical path for an include file via a trailing slash in a request to a directly accessible PHP program, which modifies the base path, causes the include directive to fail, and produces an error message that contains the path.
0
Attacker Value
Unknown
CVE-2002-0229
Disclosure Date: May 16, 2002 (last updated February 22, 2025)
Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.
0
Attacker Value
Unknown
CVE-2002-0121
Disclosure Date: March 25, 2002 (last updated February 22, 2025)
PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.
0
Attacker Value
Unknown
CVE-2002-0081
Disclosure Date: March 08, 2002 (last updated February 22, 2025)
Buffer overflows in (1) php_mime_split in PHP 4.1.0, 4.1.1, and 4.0.6 and earlier, and (2) php3_mime_split in PHP 3.0.x allows remote attackers to execute arbitrary code via a multipart/form-data HTTP POST request when file_uploads is enabled.
0