Vulnerabilities > PHP > PHP > 5.0.5
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2005-11-01 | CVE-2005-3389 | Unspecified vulnerability in PHP The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected. | 5.0 |
2005-10-27 | CVE-2005-3319 | Local Denial of Service vulnerability in PHP Apache 2 The apache2handler SAPI (sapi_apache2.c) in the Apache module (mod_php) for PHP 5.x before 5.1.0 final and 4.4 before 4.4.1 final allows attackers to cause a denial of service (segmentation fault) via the session.save_path option in a .htaccess file or VirtualHost. | 2.1 |