Show filters
116 Total Results
Displaying 61-70 of 116
Sort by:
Attacker Value
Unknown

CVE-2009-3558

Disclosure Date: November 23, 2009 (last updated October 04, 2023)
The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass open_basedir restrictions, and create FIFO files, via the pathname and mode arguments, as demonstrated by creating a .htaccess file.
0
Attacker Value
Unknown

CVE-2009-3557

Disclosure Date: November 23, 2009 (last updated October 04, 2023)
The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix arguments.
0
Attacker Value
Unknown

CVE-2009-3546

Disclosure Date: October 19, 2009 (last updated October 04, 2023)
The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-3291

Disclosure Date: September 22, 2009 (last updated October 04, 2023)
The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.
0
Attacker Value
Unknown

CVE-2009-3292

Disclosure Date: September 22, 2009 (last updated October 04, 2023)
Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."
0
Attacker Value
Unknown

CVE-2009-3293

Disclosure Date: September 22, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."
0
Attacker Value
Unknown

CVE-2009-3168

Disclosure Date: September 11, 2009 (last updated January 26, 2024)
Mevin Productions Basic PHP Events Lister 2.0 does not properly restrict access to (1) admin/reset.php and (2) admin/user_add.php, which allows remote authenticated users to reset administrative passwords or add administrators via a direct request.
0
Attacker Value
Unknown

CVE-2009-1587

Disclosure Date: May 07, 2009 (last updated October 04, 2023)
index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by setting the login_id, group_id, login_name, user_id, and user_type cookies to certain values.
0
Attacker Value
Unknown

CVE-2008-6777

Disclosure Date: May 01, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a confirm action, the (2) user parameter in a newconfirm action, and (3) reqpwd action to member.php; and the (4) quote parameter in a post action and (5) pid parameter in an edit action to post.php, different vectors than CVE-2005-0413.2 and CVE-2007-6667.
0
Attacker Value
Unknown

CVE-2008-6745

Disclosure Date: April 23, 2009 (last updated October 04, 2023)
index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a register2 action.
0