← Back

Php

php

Vendor: Php • 727 CVEs

CVEs (727)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Mandrakesoft
Php
2Mandrake Linux
Php
Apr 16, 2026
Jan 12, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP script...Show more
The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.Show less
1Php
1Php
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.
1Php
1Php
Apr 16, 2026
Nov 14, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables.
1Php
1Php
Apr 16, 2026
Jan 4, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.
1Php
1Php
Apr 16, 2026
Oct 19, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
CGI PHP mylog script allows an attacker to read any file on the target server.
1Php
1Php
Apr 16, 2026
Aug 1, 1997
N/A· v4
N/A· v3
10.0 HIGH· v2
php.cgi allows attackers to read any file on the system.
1Php
1Php
Apr 16, 2026
Apr 17, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in PHP cgi program, php.cgi allows shell access.