Vulnerabilities
Vulnerable Software
Php:  >> Php  >> 4.4.1  Security Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.
CVSS Score
2.6
EPSS Score
0.038
Published
2006-01-13
Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long named pipe variable in the host argument to the mysql_connect function.
CVSS Score
7.5
EPSS Score
0.122
Published
2006-01-06
CRLF injection vulnerability in the mb_send_mail function in PHP before 5.1.0 might allow remote attackers to inject arbitrary e-mail headers via line feeds (LF) in the "To" address argument.
CVSS Score
5.0
EPSS Score
0.031
Published
2005-11-29
php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.
CVSS Score
5.0
EPSS Score
0.097
Published
2004-11-03
rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified.
CVSS Score
2.1
EPSS Score
0.006
Published
2004-11-03


Contact Us

Shodan ® - All rights reserved