Show filters
179 Total Results
Displaying 141-150 of 179
Sort by:
Attacker Value
Unknown

CVE-2006-1017

Disclosure Date: March 07, 2006 (last updated February 22, 2025)
The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.
0
Attacker Value
Unknown

CVE-2006-1015

Disclosure Date: March 07, 2006 (last updated February 22, 2025)
Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.
0
Attacker Value
Unknown

CVE-2006-1014

Disclosure Date: March 07, 2006 (last updated February 22, 2025)
Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.
0
Attacker Value
Unknown

CVE-2006-0208

Disclosure Date: January 13, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.
0
Attacker Value
Unknown

CVE-2006-0207

Disclosure Date: January 13, 2006 (last updated February 22, 2025)
Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.
0
Attacker Value
Unknown

CVE-2005-3883

Disclosure Date: November 29, 2005 (last updated February 22, 2025)
CRLF injection vulnerability in the mb_send_mail function in PHP before 5.1.0 might allow remote attackers to inject arbitrary e-mail headers via line feeds (LF) in the "To" address argument.
0
Attacker Value
Unknown

CVE-2005-3388

Disclosure Date: November 01, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment."
0
Attacker Value
Unknown

CVE-2005-3389

Disclosure Date: November 01, 2005 (last updated February 22, 2025)
The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected.
0
Attacker Value
Unknown

CVE-2005-3390

Disclosure Date: November 01, 2005 (last updated February 22, 2025)
The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modify the GLOBALS array and bypass security protections of PHP applications via a multipart/form-data POST request with a "GLOBALS" fileupload field.
0
Attacker Value
Unknown

CVE-2005-3319

Disclosure Date: October 27, 2005 (last updated February 22, 2025)
The apache2handler SAPI (sapi_apache2.c) in the Apache module (mod_php) for PHP 5.x before 5.1.0 final and 4.4 before 4.4.1 final allows attackers to cause a denial of service (segmentation fault) via the session.save_path option in a .htaccess file or VirtualHost.
0