Vulnerabilities
Vulnerable Software
Php:  Security Vulnerabilities
PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.
CVSS Score
10.0
EPSS Score
0.206
Published
2000-12-19
The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables.
CVSS Score
5.0
EPSS Score
0.028
Published
2000-11-14
PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.
CVSS Score
10.0
EPSS Score
0.101
Published
2000-01-04
CGI PHP mylog script allows an attacker to read any file on the target server.
CVSS Score
7.5
EPSS Score
0.07
Published
1997-10-19
CGI PHP mlog script allows an attacker to read any file on the target server.
CVSS Score
5.0
EPSS Score
0.014
Published
1997-10-16
php.cgi allows attackers to read any file on the system.
CVSS Score
10.0
EPSS Score
0.061
Published
1997-08-01
Buffer overflow in PHP cgi program, php.cgi allows shell access.
CVSS Score
7.5
EPSS Score
0.018
Published
1997-04-17


Contact Us

Shodan ® - All rights reserved