Show filters
87 Total Results
Displaying 71-80 of 87
Sort by:
Attacker Value
Unknown

CVE-2010-1860

Disclosure Date: May 07, 2010 (last updated October 04, 2023)
The html_entity_decode function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal call, related to the call time pass by reference feature.
0
Attacker Value
Unknown

CVE-2010-1862

Disclosure Date: May 07, 2010 (last updated October 04, 2023)
The chunk_split function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.
0
Attacker Value
Unknown

CVE-2010-1868

Disclosure Date: May 07, 2010 (last updated October 04, 2023)
The (1) sqlite_single_query and (2) sqlite_array_query functions in ext/sqlite/sqlite.c in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to execute arbitrary code by calling these functions with an empty SQL query, which triggers access of uninitialized memory.
0
Attacker Value
Unknown

CVE-2010-1864

Disclosure Date: May 07, 2010 (last updated October 04, 2023)
The addcslashes function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.
0
Attacker Value
Unknown

CVE-2010-1861

Disclosure Date: May 07, 2010 (last updated October 04, 2023)
The sysvshm extension for PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to write to arbitrary memory addresses by using an object's __sleep function to interrupt an internal call to the shm_put_var function, which triggers access of a freed resource.
0
Attacker Value
Unknown

CVE-2010-1130

Disclosure Date: March 26, 2010 (last updated October 04, 2023)
session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the session_save_path function, which allows context-dependent attackers to bypass open_basedir and safe_mode restrictions via an argument that contains multiple ; characters in conjunction with a .. (dot dot).
0
Attacker Value
Unknown

CVE-2010-0397

Disclosure Date: March 16, 2010 (last updated October 04, 2023)
The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.
0
Attacker Value
Unknown

CVE-2008-6728

Disclosure Date: April 20, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the Sections module in PHP-Nuke, probably before 8.0, allows remote attackers to execute arbitrary SQL commands via the artid parameter in a printpage action to modules.php.
0
Attacker Value
Unknown

CVE-2007-1581

Disclosure Date: March 21, 2007 (last updated October 04, 2023)
The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file function via a userspace (1) error or (2) stream handler, which can then be used to destroy and modify internal resources. NOTE: it was later reported that PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 are also affected.
0
Attacker Value
Unknown

CVE-2004-0269

Disclosure Date: November 23, 2004 (last updated February 22, 2025)
SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.
0