Show filters
120 Total Results
Displaying 91-100 of 120
Sort by:
Attacker Value
Unknown
CVE-2006-2660
Disclosure Date: June 13, 2006 (last updated October 04, 2023)
Buffer consumption vulnerability in the tempnam function in PHP 5.1.4 and 4.x before 4.4.3 allows local users to bypass restrictions and create PHP files with fixed names in other directories via a pathname argument longer than MAXPATHLEN, which prevents a unique string from being appended to the filename.
0
Attacker Value
Unknown
CVE-2006-2149
Disclosure Date: May 03, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in sources/lostpw.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the CONFIG[path] parameter, as demonstrated by including a GIF that contains PHP code.
0
Attacker Value
Unknown
CVE-2006-1608
Disclosure Date: April 10, 2006 (last updated February 22, 2025)
The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass safe mode and read arbitrary files via a source argument containing a compress.zlib:// URI.
0
Attacker Value
Unknown
CVE-2006-1494
Disclosure Date: April 10, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.
0
Attacker Value
Unknown
CVE-2006-1490
Disclosure Date: March 29, 2006 (last updated February 22, 2025)
PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.
0
Attacker Value
Unknown
CVE-2006-1017
Disclosure Date: March 07, 2006 (last updated February 22, 2025)
The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.
0
Attacker Value
Unknown
CVE-2006-1015
Disclosure Date: March 07, 2006 (last updated February 22, 2025)
Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.
0
Attacker Value
Unknown
CVE-2006-0208
Disclosure Date: January 13, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.
0
Attacker Value
Unknown
CVE-2005-3883
Disclosure Date: November 29, 2005 (last updated February 22, 2025)
CRLF injection vulnerability in the mb_send_mail function in PHP before 5.1.0 might allow remote attackers to inject arbitrary e-mail headers via line feeds (LF) in the "To" address argument.
0
Attacker Value
Unknown
CVE-2005-3353
Disclosure Date: November 18, 2005 (last updated February 22, 2025)
The exif_read_data function in the Exif module in PHP before 4.4.1 allows remote attackers to cause a denial of service (infinite loop) via a malformed JPEG image.
0