Show filters
171 Total Results
Displaying 51-60 of 171
Sort by:
Attacker Value
Unknown
CVE-2009-2687
Disclosure Date: August 05, 2009 (last updated October 04, 2023)
The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.
0
Attacker Value
Unknown
CVE-2009-2608
Disclosure Date: July 27, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php. NOTE: the edit.php and view.php vectors are already covered by CVE-2008-2565.
0
Attacker Value
Unknown
CVE-2009-2302
Disclosure Date: July 02, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Aardvark Topsites PHP 5.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action. NOTE: it was later reported that 5.2.1 is also affected.
0
Attacker Value
Unknown
CVE-2009-2304
Disclosure Date: July 02, 2009 (last updated October 04, 2023)
index.php in Aardvark Topsites PHP 5.2.0 and earlier allows remote attackers to obtain sensitive information via a nonexistent account name in the u parameter in a rate action, which reveals the installation path in an error message.
0
Attacker Value
Unknown
CVE-2009-2303
Disclosure Date: July 02, 2009 (last updated October 04, 2023)
index.php in Aardvark Topsites PHP 5.2.1 and earlier allows remote attackers to obtain sensitive information via a negative integer value for the start parameter in a search action, which reveals the installation path in an error message.
0
Attacker Value
Unknown
CVE-2008-5946
Disclosure Date: January 22, 2009 (last updated October 04, 2023)
SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parameter.
0
Attacker Value
Unknown
CVE-2008-5814
Disclosure Date: January 02, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in PHP, possibly 5.2.7 and earlier, when display_errors is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: because of the lack of details, it is unclear whether this is related to CVE-2006-0208.
0
Attacker Value
Unknown
CVE-2008-4107
Disclosure Date: September 18, 2008 (last updated October 04, 2023)
The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in products that rely on these functions for security-relevant functionality, as demonstrated by the password-reset functionality in Joomla! 1.5.x and WordPress before 2.6.2, a different vulnerability than CVE-2008-2107, CVE-2008-2108, and CVE-2008-4102.
0
Attacker Value
Unknown
CVE-2008-2371
Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.
0
Attacker Value
Unknown
CVE-2008-2108
Disclosure Date: May 07, 2008 (last updated February 15, 2024)
The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a portion of zero bits during conversion due to insufficient precision, which produces 24 bits of entropy and simplifies brute force attacks against protection mechanisms that use the rand and mt_rand functions.
0