← Back

Php

php

757 CVEs • 25 products

Products (25)

Click to collapse
Toggle
Php
php
Pear
pear
Archive Tar
archive_tar
Pearweb
pearweb
Frankenphp
frankenphp
Phpsquidpass
phpsquidpass
Xml Rpc
xml_rpc
Errordocs
errordocs
Blog Cms
blog_cms
Bloq
bloq
Com Extensions
com_extensions
Xhprof
xhprof
Pecl Http
pecl_http
Imagick
imagick
Ext Http
ext-http
Memcached
memcached
Php Fi
php_fi

CVEs (757)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Php
1Php
Apr 16, 2026
Apr 10, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.
1Php
1Php
Apr 16, 2026
Apr 10, 2006
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (...Show more
Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.Show less
1Php
1Php Script Index
Apr 16, 2026
Mar 31, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in PHP Script Index allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely fro...Show more
SQL injection vulnerability in PHP Script Index allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Php
1Php Script Index
Apr 16, 2026
Mar 31, 2006
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in search.php in PHP Script Index allows remote attackers to inject arbitrary web script or HTML via the search parameter.
1Php
1Php
Apr 16, 2026
Mar 29, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to t...Show more
PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.Show less
1Php
1Php
Apr 16, 2026
Mar 7, 2006
N/A· v4
N/A· v3
9.3 HIGH· v2
The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mai...Show more
The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.Show less
1Php
1Php
Apr 16, 2026
Mar 7, 2006
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers...Show more
Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.Show less
1Php
1Php
Apr 16, 2026
Mar 7, 2006
N/A· v4
N/A· v3
3.2 LOW· v2
Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-depend...Show more
Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.Show less
1Php
1Php
Apr 16, 2026
Jan 13, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that ar...Show more
Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.Show less
1Php
1Php
Apr 16, 2026
Jan 13, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) he...Show more
Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.Show less
1Php
1Php
Apr 16, 2026
Jan 13, 2006
N/A· v4
N/A· v3
9.3 HIGH· v2
Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.
2Apache2triad
Php
2Apache2triad
Pear
Apr 16, 2026
Jan 9, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified ve...Show more
The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.Show less
1Php
1Php
Apr 16, 2026
Jan 6, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argum...Show more
Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long named pipe variable in the host argument to the mysql_connect function.Show less
1Php
1Pear
Apr 16, 2026
Dec 11, 2005
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Unspecified vulnerability in PEAR installer 1.4.2 and earlier allows user-assisted attackers to execute arbitrary code via a crafted package that can execute code when the pear command is executed or when the Web/Gtk fro...Show more
Unspecified vulnerability in PEAR installer 1.4.2 and earlier allows user-assisted attackers to execute arbitrary code via a crafted package that can execute code when the pear command is executed or when the Web/Gtk frontend is loaded.Show less
1Php
1Php
Apr 16, 2026
Nov 29, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
CRLF injection vulnerability in the mb_send_mail function in PHP before 5.1.0 might allow remote attackers to inject arbitrary e-mail headers via line feeds (LF) in the "To" address argument.
1Php
1Php
Apr 16, 2026
Nov 18, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The exif_read_data function in the Exif module in PHP before 4.4.1 allows remote attackers to cause a denial of service (infinite loop) via a malformed JPEG image.
1Php
1Php
Apr 16, 2026
Nov 1, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in PHP before 4.4.1, when using the virtual function on Apache 2, allows remote attackers to bypass safe_mode and open_basedir directives.
1Php
1Php
Apr 16, 2026
Nov 1, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple vulnerabilities in PHP before 4.4.1 allow remote attackers to bypass safe_mode and open_basedir restrictions via unknown attack vectors in (1) ext/curl and (2) ext/gd.
1Php
1Php
Apr 16, 2026
Nov 1, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modify the GLOBALS array and bypass security protections of PHP applications via a...Show more
The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modify the GLOBALS array and bypass security protections of PHP applications via a multipart/form-data POST request with a "GLOBALS" fileupload field.Show less
1Php
1Php
Apr 16, 2026
Nov 1, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated du...Show more
The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected.Show less