Computer Security
[EN] securityvulns.ru
no-pyccku



See also
  PHP : PHP 5.4
  PHP : PHP 5.3
  AARDVARK : Aardvark Topsites PHP 5.2
  PHP : PHP 5,2
  AARDVARDTOPSITES : Aardvark Topsites PHP 5.1
  ATSPHP : Atsphp 5.0
  DOTDEB : Dotdeb PHP 5.2
  PHP : PHP 5.2
  PHP : PHP 5.1
  DTHEATRE : Jacks FormMail.php 5.0
Name:PHP : PHP 5.0

6!PHP ip2long protection bypass
document Function can return positive result on malformed argument, it can be used to bypass argument validation.
6!Multiple PHP vulnerabilities
updated since 31.10.2005
document phpinfo() crossite scripting, parse_str() register_globals activisation possibility, $GLOBALS variable modification witrh HTTP POST form 'fileupload' field. It's also possible to modify any variable with GLOBALS[variable].
 Multiple PHP extensions vulnerabilities
document mysqli extension format string vulnerability, session extension session id HTTP response splitting.
 PHP Apache configuration files DoS
document Server crashes on invalid .htaccess 'php_value session.save_path' value.
 PHP open_basedir protection bypass
updated since 28.09.2005
document Under some rare conditions it's possible to open file from different directory.
 PHP multiple vulnerabilities
updated since 13.04.2005
document Integer overflows on EXIF tags parsing.
 PHP getimagesize DoS
document Infinite loops with 100% CPU utilization.
7!Multiple PHP bugs
updated since 16.12.2004
document Integer overflow leading to memory content leak, safe mode protection bypass, openlog() buffer overflow, etc.
7!Multiple PHP request parsing bugs
updated since 16.09.2004
document Invalid request parameters parsing leads to leakage of memory content and rewriting of internal variables.
6!PHP memory corruption
document Invalid exceptional conditions handling allows memory corruption leading to code execution.
 PHP strip_tags protection bypass
document Insertion null character into tag allow protection bypass for few browsers.
                    

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server