Page 107 of 535 results (0.010 seconds)

CVSS: 5.0EPSS: 0%CPEs: 18EXPL: 1

The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables. • http://archives.neohapsis.com/archives/bugtraq/2000-08/0455.html http://archives.neohapsis.com/archives/bugtraq/2000-08/0477.html http://archives.neohapsis.com/archives/bugtraq/2000-09/0150.html http://cvsweb.php.net/viewcvs.cgi/php4/main/rfc1867.c.diff?r1=1.38%3Aphp_4_0_2&tr1=1.1&r2=text&tr2=1.45&diff_format=u http://www.securityfocus.com/bid/1649 https://exchange.xforce.ibmcloud.com/vulnerabilities/5190 •

CVSS: 10.0EPSS: 6%CPEs: 14EXPL: 1

PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands. • https://www.exploit-db.com/exploits/19708 http://www.securityfocus.com/bid/911 •

CVSS: 7.5EPSS: 1%CPEs: 3EXPL: 1

CGI PHP mylog script allows an attacker to read any file on the target server. • https://www.exploit-db.com/exploits/19553 http://www.osvdb.org/3396 http://www.securityfocus.com/bid/713 •

CVSS: 10.0EPSS: 1%CPEs: 3EXPL: 1

php.cgi allows attackers to read any file on the system. • https://www.exploit-db.com/exploits/20567 https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0238 •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

Buffer overflow in PHP cgi program, php.cgi allows shell access. • http://www.securityfocus.com/bid/712 •