Vulnerabilities > PHP > PHP > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-08-29 | CVE-2006-4433 | Remote Security vulnerability in PHP PHP before 4.4.3 and 5.x before 5.1.4 does not limit the character set of the session identifier (PHPSESSID) for third party session handlers, which might make it easier for remote attackers to exploit other vulnerabilities by inserting PHP code into the PHPSESSID, which is stored in the session file. | 7.5 |
2006-01-06 | CVE-2006-0097 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in PHP Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long named pipe variable in the host argument to the mysql_connect function. | 7.5 |
2005-11-01 | CVE-2005-3392 | Unspecified vulnerability in PHP Unspecified vulnerability in PHP before 4.4.1, when using the virtual function on Apache 2, allows remote attackers to bypass safe_mode and open_basedir directives. | 7.5 |
2005-11-01 | CVE-2005-3391 | Safe_Mode and Open_Basedir Restriction Bypass vulnerability in PHP cURL and GD Multiple vulnerabilities in PHP before 4.4.1 allow remote attackers to bypass safe_mode and open_basedir restrictions via unknown attack vectors in (1) ext/curl and (2) ext/gd. | 7.5 |
2005-11-01 | CVE-2005-3390 | Unspecified vulnerability in PHP The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modify the GLOBALS array and bypass security protections of PHP applications via a multipart/form-data POST request with a "GLOBALS" fileupload field. | 7.5 |
2005-05-02 | CVE-2005-1042 | Unspecified vulnerability in PHP Integer overflow in the exif_process_IFD_TAG function in exif.c in PHP before 4.3.11 may allow remote attackers to execute arbitrary code via an IFD tag that leads to a negative byte count. | 7.5 |
2003-11-17 | CVE-2003-0863 | Unspecified vulnerability in PHP 4.3.0/4.3.1/4.3.2 The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir variable is not specified in configuration, which differs from the previous failure value and may allow remote attackers to exploit file include vulnerabilities in PHP applications. | 7.5 |
2003-04-02 | CVE-2003-0172 | Buffer Overflow vulnerability in PHP 4.3.1 Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote attackers to cause a crash and possibly execute arbitrary code via a long filename argument. | 7.5 |
2003-04-02 | CVE-2003-0166 | Unspecified vulnerability in PHP Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions. | 7.5 |
2003-03-03 | CVE-2003-0097 | Unspecified vulnerability in PHP 4.3.0 Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect). | 7.5 |