Show filters
116 Total Results
Displaying 91-100 of 116
Sort by:
Attacker Value
Unknown
CVE-2007-1461
Disclosure Date: March 14, 2007 (last updated October 04, 2023)
The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP before 4.4.7, and 5.x before 5.2.2, does not implement safemode or open_basedir checks, which allows remote attackers to read bzip2 archives located outside of the intended directories.
0
Attacker Value
Unknown
CVE-2007-1460
Disclosure Date: March 14, 2007 (last updated October 04, 2023)
The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.
0
Attacker Value
Unknown
CVE-2007-1285
Disclosure Date: March 06, 2007 (last updated February 03, 2024)
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.
0
Attacker Value
Unknown
CVE-2006-6360
Disclosure Date: December 07, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in activate.php in PHP Upload Center 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the footerpage parameter.
0
Attacker Value
Unknown
CVE-2006-4051
Disclosure Date: August 10, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter.
0
Attacker Value
Unknown
CVE-2006-3011
Disclosure Date: June 26, 2006 (last updated October 04, 2023)
The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe mode and open_basedir restrictions via a "php://" or other scheme in the third argument, which disables safe mode.
0
Attacker Value
Unknown
CVE-2006-3062
Disclosure Date: June 19, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in myPHP Guestbook 2.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
0
Attacker Value
Unknown
CVE-2006-3063
Disclosure Date: June 19, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in myPHP Guestbook 1.x through 2.0.0-r1 and before 2.0.1 RC5 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) email, (3) homepage, (4) id, (5) name, and (6) text parameters in (a) index.php, the (7) comment, (8) email, (9) homepage, (10) number, (11) name, and (12) text parameters in (b) admin/guestbook.php, and the (13) email, (14) homepage, (15) icq, (16) name, and (17) text parameters in (c) admin/edit.php.
0
Attacker Value
Unknown
CVE-2006-1291
Disclosure Date: March 19, 2006 (last updated February 22, 2025)
publish.ical.php in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier does not require authentication for write access to the calendars directory, which allows remote attackers to upload and execute arbitrary PHP scripts via a WebDAV PUT request with a filename containing a .php extension and a trailing null character.
0
Attacker Value
Unknown
CVE-2006-1292
Disclosure Date: March 19, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.
0