Show filters
118 Total Results
Displaying 41-50 of 118
Sort by:
Attacker Value
Unknown
CVE-2009-4018
Disclosure Date: November 29, 2009 (last updated October 04, 2023)
The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_vars directives, which allows context-dependent attackers to execute programs with an arbitrary environment via the env parameter, as demonstrated by a crafted value of the LD_LIBRARY_PATH environment variable.
0
Attacker Value
Unknown
CVE-2009-3558
Disclosure Date: November 23, 2009 (last updated October 04, 2023)
The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass open_basedir restrictions, and create FIFO files, via the pathname and mode arguments, as demonstrated by creating a .htaccess file.
0
Attacker Value
Unknown
CVE-2009-3557
Disclosure Date: November 23, 2009 (last updated October 04, 2023)
The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix arguments.
0
Attacker Value
Unknown
CVE-2009-3291
Disclosure Date: September 22, 2009 (last updated October 04, 2023)
The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.
0
Attacker Value
Unknown
CVE-2009-3292
Disclosure Date: September 22, 2009 (last updated October 04, 2023)
Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."
0
Attacker Value
Unknown
CVE-2009-3293
Disclosure Date: September 22, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."
0
Attacker Value
Unknown
CVE-2008-7068
Disclosure Date: August 25, 2009 (last updated October 04, 2023)
The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in which the attacker can modify or add database entries but does not have permissions to truncate the file.
0
Attacker Value
Unknown
CVE-2009-2608
Disclosure Date: July 27, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php. NOTE: the edit.php and view.php vectors are already covered by CVE-2008-2565.
0
Attacker Value
Unknown
CVE-2009-2302
Disclosure Date: July 02, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Aardvark Topsites PHP 5.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action. NOTE: it was later reported that 5.2.1 is also affected.
0
Attacker Value
Unknown
CVE-2009-2304
Disclosure Date: July 02, 2009 (last updated October 04, 2023)
index.php in Aardvark Topsites PHP 5.2.0 and earlier allows remote attackers to obtain sensitive information via a nonexistent account name in the u parameter in a rate action, which reveals the installation path in an error message.
0