Show filters
171 Total Results
Displaying 161-170 of 171
Sort by:
Attacker Value
Unknown

CVE-2002-0206

Disclosure Date: May 16, 2002 (last updated February 22, 2025)
index.php in Francisco Burzi PHP-Nuke 5.3.1 and earlier, and possibly other versions before 5.5, allows remote attackers to execute arbitrary PHP code by specifying a URL to the malicious code in the file parameter.
0
Attacker Value
Unknown

CVE-2002-0229

Disclosure Date: May 16, 2002 (last updated February 22, 2025)
Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.
0
Attacker Value
Unknown

CVE-2002-0121

Disclosure Date: March 25, 2002 (last updated February 22, 2025)
PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.
0
Attacker Value
Unknown

CVE-2002-0081

Disclosure Date: March 08, 2002 (last updated February 22, 2025)
Buffer overflows in (1) php_mime_split in PHP 4.1.0, 4.1.1, and 4.0.6 and earlier, and (2) php3_mime_split in PHP 3.0.x allows remote attackers to execute arbitrary code via a multipart/form-data HTTP POST request when file_uploads is enabled.
0
Attacker Value
Unknown

CVE-2001-1524

Disclosure Date: December 31, 2001 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) uname parameter in user.php, (2) ttitle, letter and file parameters in modules.php, (3) subject, story and storyext parameters in submit.php, (4) upload parameter in admin.php and (5) fname parameter in friend.php.
0
Attacker Value
Unknown

CVE-2001-1247

Disclosure Date: December 06, 2001 (last updated February 22, 2025)
PHP 4.0.4pl1 and 4.0.5 in safe mode allows remote attackers to read and write files owned by the web server UID by uploading a PHP script that uses the error_log function to access the files.
0
Attacker Value
Unknown

CVE-2001-0320

Disclosure Date: May 03, 2001 (last updated February 22, 2025)
bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.
0
Attacker Value
Unknown

CVE-2001-0108

Disclosure Date: March 12, 2001 (last updated February 22, 2025)
PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.
0
Attacker Value
Unknown

CVE-2001-1385

Disclosure Date: January 12, 2001 (last updated February 22, 2025)
The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.
0
Attacker Value
Unknown

CVE-2000-0967

Disclosure Date: December 19, 2000 (last updated February 22, 2025)
PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.
0