Vulnerabilities > PHP > PHP > 4.0.1

DATE CVE VULNERABILITY TITLE RISK
2002-08-12 CVE-2002-0484 Unspecified vulnerability in PHP
move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system.
network
low complexity
php
5.0
2002-05-29 CVE-2002-0253 Information Disclosure vulnerability in PHP Include File Relative Directory
PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote attackers to obtain the physical path for an include file via a trailing slash in a request to a directly accessible PHP program, which modifies the base path, causes the include directive to fail, and produces an error message that contains the path.
network
low complexity
php
5.0
2002-05-16 CVE-2002-0229 Unspecified vulnerability in PHP
Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.
network
low complexity
php
7.5
2001-03-12 CVE-2001-0108 PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.
network
low complexity
php mandrakesoft
5.0
2001-01-12 CVE-2001-1385 The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.
network
low complexity
php mandrakesoft
5.0