Show filters
171 Total Results
Displaying 161-170 of 171
Sort by:
Attacker Value
Unknown
CVE-2002-0206
Disclosure Date: May 16, 2002 (last updated February 22, 2025)
index.php in Francisco Burzi PHP-Nuke 5.3.1 and earlier, and possibly other versions before 5.5, allows remote attackers to execute arbitrary PHP code by specifying a URL to the malicious code in the file parameter.
0
Attacker Value
Unknown
CVE-2002-0229
Disclosure Date: May 16, 2002 (last updated February 22, 2025)
Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.
0
Attacker Value
Unknown
CVE-2002-0121
Disclosure Date: March 25, 2002 (last updated February 22, 2025)
PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.
0
Attacker Value
Unknown
CVE-2002-0081
Disclosure Date: March 08, 2002 (last updated February 22, 2025)
Buffer overflows in (1) php_mime_split in PHP 4.1.0, 4.1.1, and 4.0.6 and earlier, and (2) php3_mime_split in PHP 3.0.x allows remote attackers to execute arbitrary code via a multipart/form-data HTTP POST request when file_uploads is enabled.
0
Attacker Value
Unknown
CVE-2001-1524
Disclosure Date: December 31, 2001 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) uname parameter in user.php, (2) ttitle, letter and file parameters in modules.php, (3) subject, story and storyext parameters in submit.php, (4) upload parameter in admin.php and (5) fname parameter in friend.php.
0
Attacker Value
Unknown
CVE-2001-1247
Disclosure Date: December 06, 2001 (last updated February 22, 2025)
PHP 4.0.4pl1 and 4.0.5 in safe mode allows remote attackers to read and write files owned by the web server UID by uploading a PHP script that uses the error_log function to access the files.
0
Attacker Value
Unknown
CVE-2001-0320
Disclosure Date: May 03, 2001 (last updated February 22, 2025)
bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.
0
Attacker Value
Unknown
CVE-2001-0108
Disclosure Date: March 12, 2001 (last updated February 22, 2025)
PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.
0
Attacker Value
Unknown
CVE-2001-1385
Disclosure Date: January 12, 2001 (last updated February 22, 2025)
The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.
0
Attacker Value
Unknown
CVE-2000-0967
Disclosure Date: December 19, 2000 (last updated February 22, 2025)
PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.
0