Show filters
117 Total Results
Displaying 41-50 of 117
Sort by:
Attacker Value
Unknown
CVE-2010-1130
Disclosure Date: March 26, 2010 (last updated October 04, 2023)
session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the session_save_path function, which allows context-dependent attackers to bypass open_basedir and safe_mode restrictions via an argument that contains multiple ; characters in conjunction with a .. (dot dot).
0
Attacker Value
Unknown
CVE-2009-4418
Disclosure Date: December 24, 2009 (last updated October 04, 2023)
The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.
0
Attacker Value
Unknown
CVE-2009-4143
Disclosure Date: December 21, 2009 (last updated October 04, 2023)
PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.
0
Attacker Value
Unknown
CVE-2009-2626
Disclosure Date: December 01, 2009 (last updated October 04, 2023)
The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive information (memory contents) and cause a PHP crash by using the ini_set function to declare a variable, then using the ini_restore function to restore the variable.
0
Attacker Value
Unknown
CVE-2009-4018
Disclosure Date: November 29, 2009 (last updated October 04, 2023)
The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_vars directives, which allows context-dependent attackers to execute programs with an arbitrary environment via the env parameter, as demonstrated by a crafted value of the LD_LIBRARY_PATH environment variable.
0
Attacker Value
Unknown
CVE-2009-3291
Disclosure Date: September 22, 2009 (last updated October 04, 2023)
The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.
0
Attacker Value
Unknown
CVE-2009-3292
Disclosure Date: September 22, 2009 (last updated October 04, 2023)
Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."
0
Attacker Value
Unknown
CVE-2009-3293
Disclosure Date: September 22, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."
0
Attacker Value
Unknown
CVE-2009-2302
Disclosure Date: July 02, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Aardvark Topsites PHP 5.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action. NOTE: it was later reported that 5.2.1 is also affected.
0
Attacker Value
Unknown
CVE-2009-2304
Disclosure Date: July 02, 2009 (last updated October 04, 2023)
index.php in Aardvark Topsites PHP 5.2.0 and earlier allows remote attackers to obtain sensitive information via a nonexistent account name in the u parameter in a rate action, which reveals the installation path in an error message.
0