Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2011-5021

Disclosure Date: December 29, 2011 (last updated October 04, 2023)
PHPIDS before 0.7 does not properly implement Regular Expression Denial of Service (ReDoS) filters, which allows remote attackers to bypass rulesets and add PHP sequences to a file via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-3781

Disclosure Date: September 24, 2011 (last updated October 04, 2023)
PHPIDS 0.6.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/IDS/VersionTest.php and certain other files.
0
Attacker Value
Unknown

CVE-2007-3579

Disclosure Date: July 05, 2007 (last updated October 04, 2023)
PHPIDS before 20070703 does not properly handle setting the .text property of a SCRIPT element before its attachment to the DOM, which allows remote attackers to inject arbitrary web script.
0
Attacker Value
Unknown

CVE-2007-3577

Disclosure Date: July 05, 2007 (last updated October 04, 2023)
PHPIDS before 20070703 does not properly handle use of the substr method in (1) document.location.search and (2) document.referrer; (3) certain use of document.location.hash; (4) certain "window[eval" and similar expressions; (5) certain Function expressions; (6) certain '=' expressions, as demonstrated by a 'whatever="something"' sequence; and (7) certain "with" expressions, which allows remote attackers to inject arbitrary web script.
0
Attacker Value
Unknown

CVE-2007-3578

Disclosure Date: July 05, 2007 (last updated October 04, 2023)
PHPIDS before 20070703 does not properly handle (1) arithmetic expressions and (2) unclosed comments, which allows remote attackers to inject arbitrary web script.
0
Attacker Value
Unknown

CVE-2007-3580

Disclosure Date: July 05, 2007 (last updated October 04, 2023)
PHPIDS does not properly handle certain code containing newlines, as demonstrated by a try/catch block within a loop, which allows user-assisted remote attackers to inject arbitrary web script.
0