Show filters
57 Total Results
Displaying 51-57 of 57
Sort by:
Attacker Value
Unknown
CVE-2007-1370
Disclosure Date: March 09, 2007 (last updated October 04, 2023)
Zend Platform 2.2.3 and earlier has incorrect ownership for scd.sh and certain other files, which allows local users to gain root privileges by modifying the files. NOTE: this only occurs when safe_mode and open_basedir are disabled; other settings require leverage for other vulnerabilities.
0
Attacker Value
Unknown
CVE-2007-1369
Disclosure Date: March 09, 2007 (last updated October 04, 2023)
ini_modifier (sgid-zendtech) in Zend Platform 2.2.3 and earlier allows local users to modify the system php.ini file by editing a copy of php.ini file using the -f parameter, and then performing a symlink attack using the directory that contains the attacker-controlled php.ini file, and linking this directory to /usr/local/Zend/etc.
0
Attacker Value
Unknown
CVE-2006-5900
Disclosure Date: November 15, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the incubator/tests/Zend/Http/_files/testRedirections.php sample code in Zend Framework Preview 0.2.0 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters.
0
Attacker Value
Unknown
CVE-2006-5717
Disclosure Date: November 04, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Zend Google Data Client Library (ZendGData) Preview 0.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) basedemo.php and (2) calenderdemo.php in samples/, and other unspecified files.
0
Attacker Value
Unknown
CVE-2006-4432
Disclosure Date: August 29, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in Zend Platform 2.2.1 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the final component of the PHP session identifier (PHPSESSID). NOTE: in some cases, this issue can be leveraged to perform direct static code injection.
0
Attacker Value
Unknown
CVE-2006-4431
Disclosure Date: August 29, 2006 (last updated October 04, 2023)
Multiple buffer overflows in the (a) Session Clustering Daemon and the (b) mod_cluster module in the Zend Platform 2.2.1 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a (1) empty or (2) crafted PHP session identifier (PHPSESSID).
0
Attacker Value
Unknown
CVE-2002-2158
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
zenTrack 2.0.3 and earlier allows remote attackers to obtain the full path to the web root via an invalid ticket ID, which leaks the path in an error message.
0