Show filters
120 Total Results
Displaying 41-50 of 120
Sort by:
Attacker Value
Unknown
CVE-2009-3291
Disclosure Date: September 22, 2009 (last updated October 04, 2023)
The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.
0
Attacker Value
Unknown
CVE-2009-3292
Disclosure Date: September 22, 2009 (last updated October 04, 2023)
Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."
0
Attacker Value
Unknown
CVE-2009-3293
Disclosure Date: September 22, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."
0
Attacker Value
Unknown
CVE-2008-7068
Disclosure Date: August 25, 2009 (last updated October 04, 2023)
The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in which the attacker can modify or add database entries but does not have permissions to truncate the file.
0
Attacker Value
Unknown
CVE-2009-2302
Disclosure Date: July 02, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Aardvark Topsites PHP 5.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action. NOTE: it was later reported that 5.2.1 is also affected.
0
Attacker Value
Unknown
CVE-2009-2304
Disclosure Date: July 02, 2009 (last updated October 04, 2023)
index.php in Aardvark Topsites PHP 5.2.0 and earlier allows remote attackers to obtain sensitive information via a nonexistent account name in the u parameter in a rate action, which reveals the installation path in an error message.
0
Attacker Value
Unknown
CVE-2009-2303
Disclosure Date: July 02, 2009 (last updated October 04, 2023)
index.php in Aardvark Topsites PHP 5.2.1 and earlier allows remote attackers to obtain sensitive information via a negative integer value for the start parameter in a search action, which reveals the installation path in an error message.
0
Attacker Value
Unknown
CVE-2008-5814
Disclosure Date: January 02, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in PHP, possibly 5.2.7 and earlier, when display_errors is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: because of the lack of details, it is unclear whether this is related to CVE-2006-0208.
0
Attacker Value
Unknown
CVE-2008-4107
Disclosure Date: September 18, 2008 (last updated October 04, 2023)
The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in products that rely on these functions for security-relevant functionality, as demonstrated by the password-reset functionality in Joomla! 1.5.x and WordPress before 2.6.2, a different vulnerability than CVE-2008-2107, CVE-2008-2108, and CVE-2008-4102.
0
Attacker Value
Unknown
CVE-2007-4658
Disclosure Date: September 04, 2007 (last updated October 04, 2023)
The money_format function in PHP 5 before 5.2.4, and PHP 4 before 4.4.8, permits multiple (1) %i and (2) %n tokens, which has unknown impact and attack vectors, possibly related to a format string vulnerability.
0