CVEs (727)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP script...Show more |
PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs. |
The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables. |
PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands. |
CGI PHP mylog script allows an attacker to read any file on the target server. |
php.cgi allows attackers to read any file on the system. |
Buffer overflow in PHP cgi program, php.cgi allows shell access. |