«
Expand/Collapse
1492 items tagged "php"
Related tags:
service [+],
proof of concept [+],
malicious user [+],
form [+],
exif [+],
sql injection [+],
hash collision [+],
code execution [+],
backdoor [+],
process [+],
multiple [+],
injection [+],
information disclosure vulnerability [+],
cross [+],
bypass [+],
book [+],
vulnerability [+],
webapps [+],
volunteer management [+],
volunteer [+],
sql [+],
site [+],
poc [+],
null [+],
management version [+],
management [+],
httpd daemon [+],
hash value [+],
file [+],
extension [+],
event [+],
code [+],
calendar [+],
arbitrary code [+],
apache http server [+],
address [+],
quotes [+],
grade book [+],
gpc [+],
gift registry [+],
gift [+],
execution [+],
directive [+],
cgi [+],
buffer overflow [+],
webid [+],
web server [+],
ticket system [+],
ticket [+],
registry [+],
register [+],
php gallery [+],
php files [+],
null pointer [+],
memory limit [+],
memory [+],
linux [+],
htmlspecialchars [+],
gallery [+],
eregi [+],
encoder [+],
dsa [+],
carbylamine [+],
bugtraq [+],
book 6 [+],
beta [+],
argument [+],
xcat [+],
website [+],
webcalendar [+],
web interface [+],
vulnerabilities [+],
versions [+],
version 6 [+],
vbseo [+],
upload [+],
ubuntu [+],
system [+],
syntax [+],
stack buffer [+],
signatures [+],
shell [+],
security vulnerabilities [+],
ringtone [+],
proof [+],
proc [+],
php web [+],
php version [+],
php variables [+],
php email [+],
page [+],
overflow [+],
netcatphpshell [+],
membership [+],
mandriva linux [+],
mandriva [+],
manager script [+],
jpg jpeg [+],
input variables [+],
inline image [+],
information disclosure [+],
inclusion [+],
ibby sql [+],
ibby [+],
horde [+],
hash values [+],
grade [+],
globals [+],
fpm [+],
file upload [+],
file php [+],
event calendar [+],
email [+],
deutf [+],
content management framework [+],
configuration php [+],
com [+],
cmf [+],
buffer [+],
array variables [+],
apprain [+],
annuaire [+],
agenda 2 [+],
agenda [+],
address book [+],
denial of service [+],
x86 linux [+],
traversal [+],
socket [+],
simple [+],
shell metacharacters [+],
search [+],
remote [+],
read [+],
query string [+],
picture [+],
php 5 [+],
phalbum [+],
null character [+],
mdvsa [+],
index [+],
gallery script [+],
galette [+],
function [+],
forgery [+],
exploit [+],
encaps [+],
directory traversal vulnerability [+],
directory [+],
designer [+],
csrf [+],
character [+],
buffer overflow vulnerability [+],
arbitrary code execution [+],
red hat security [+],
red [+],
hat [+],
zip extension [+],
zip [+],
wordpress [+],
win [+],
virus detection [+],
v cms [+],
synology [+],
symlink [+],
svn [+],
survey creator [+],
suhosin [+],
station photo [+],
softbiz [+],
shmop [+],
seo [+],
restriction [+],
remote exploit [+],
regression [+],
qry [+],
portal script [+],
pointer [+],
phpmv [+],
phpmoneybooks [+],
php5 [+],
php sql [+],
php form [+],
photo station [+],
photo one [+],
photo [+],
openconf [+],
minicms [+],
memory leak [+],
lowbids [+],
lob [+],
getimagesize [+],
functions [+],
fiche [+],
dos [+],
dolibarr [+],
directory software [+],
diagnose [+],
devs [+],
cryptography [+],
cms [+],
city portal [+],
city [+],
churchcms [+],
black box test [+],
basedir [+],
base [+],
auctions [+],
advisory [+],
adherents [+],
address book view [+],
php interpreter [+],
day [+],
service vulnerability [+],
security [+],
web [+],
integer overflow vulnerability [+],
denial [+],
cross site scripting [+],
php versions [+],
php code [+],
information [+],
disclosure [+],
zylone,
ziparchive,
zephyrus cms,
zephyrus,
zend engine,
zend,
zaki cms,
zaki,
zabbix,
ypninc,
y serendipity,
xss,
xor,
xoops,
xmlrpc,
xml rpc,
xml,
xigroup,
xbtit,
xampp,
x links,
wsh,
wscms,
wp lytebox,
wp admin,
whmcs,
whizzy,
whitepaper,
wespa,
weevely,
webthaiapp,
webrcsdiff,
webkatalog,
webinspire,
weberp,
webedition,
webdav,
webcms,
webboard,
web sql,
web solutions,
web solution,
web scripts,
web script,
web root,
web products,
web photo album,
web monitor,
web messenger,
web art,
web application security,
wares,
wafer,
vuln,
visitor logger,
visitor,
virtuemart,
virtualismi,
village,
viewver,
viewtopic,
viewpost,
view,
vidiscript,
video script,
video,
version,
vbulletin,
validator,
validate,
usn,
user,
use,
usa,
url,
uri,
uploadvideos,
uploader,
upload php,
upgrade,
unserializer,
universal web,
universal,
ultravintage,
ultimate,
ugia,
txt,
try,
trojans,
trixbox,
triburom,
traverser,
transliterate,
transfer manager,
transfer,
trainers,
traidnt,
trading,
traceable,
topbiz,
top,
timthumb,
timeclock software,
tickets,
thumb,
thehostingtool,
tgz,
textpattern,
tempnam,
technology,
tcw,
target,
tar gz,
tar,
tactivefileupload,
systems,
system v1,
system modules,
system input,
system 1,
syrian,
supernews,
suite,
substr,
subkarma,
strtod,
string type,
stream,
strcut,
str,
storefronts,
store,
stonedetails,
step,
stefan esser,
statistics,
state,
stack,
sst,
ssa,
squadra,
sqlite,
sqlinfospider,
sql queries,
sql news,
sql commands,
sql code,
splobjectstorage,
spidanews,
sphider,
speedy,
southburn,
source code,
sonucozet,
solution,
software sql,
socialware,
snortreport,
snooping,
snografx,
snapproof,
smarty,
smartplugs,
smartcms,
slooze,
slogin,
slogan,
slideshowpro,
sleep mode,
skadate,
sites,
siteframe,
site software,
simploo,
simplephpweb,
silverplane,
sid,
showgallery,
show,
shoutcms,
shortcms,
shopzilla,
shopping,
shop cart,
shop,
shipkey,
sheller,
sezioni,
setup script,
setup php,
setsymbol,
seti home,
seti,
session management,
session files,
session encryption,
session,
services menu,
sell,
security vulnerability,
security summary,
security measures,
securimage,
secureurl,
section,
searchresult,
searchautocomplete,
search bible,
scripts,
script version,
script sql,
script php,
script injection,
script gallery,
script error,
script directory,
script code,
script,
scheda,
scanners,
scanner,
sardus,
sana,
sahana,
safe mode,
saa,
s.a.r.l el mithak,
s parameter,
rus,
runtime,
rubrique,
rop,
rogiobiz,
rng,
ricetta,
rhinos,
rfi,
retired,
resin,
reset password,
rental,
remote shell,
remote security,
remote file include vulnerability,
remote admin,
reminder,
register globals,
recipes,
realty,
realestate,
realadmin,
real estate listing,
real estate,
real,
read id,
ravviva,
rapidkill,
raphael geisert,
random number generator,
quickphp,
quickdev,
quick,
question,
query function,
query engine,
query,
quadri,
punbb,
publifarm,
pseudorandom number generator,
protecting,
property,
promiscuous,
project,
program,
proftp,
profileinfo,
product list,
product catalog,
product,
prodotto,
prodotti,
pro forum,
privilege,
privat,
printview,
print,
precision products,
precision,
preauth,
pre,
prado,
posix,
portals,
portal,
popup,
poll index,
poll,
poisoning,
pointter,
point,
pmwiki,
plus,
player,
play,
platinum,
place,
phuploader,
phpscheduleit,
phprs,
phpplanner,
phportal,
phpmyadmin,
phpldapadmin,
phpkit,
phpjackal,
phpid,
phpfk,
phpdirector,
phpcoin,
phpcms,
phpbb2,
phpbb,
phpauctionsystem,
php zend,
php vulnerability,
php uploader,
php upload,
php shell,
php session,
php scripts,
php script,
php project,
php nuke modules,
php nuke module,
php nuke,
php news,
php mailer,
php kit,
php index,
php guestbook,
php gd,
php fusion,
php functions,
php forum script,
php forum,
php extension,
php content management system,
php content management,
php captcha,
php board,
php asp,
php applications,
php 4,
photopost,
photogallery,
photo gallery,
photo album,
phonecdirectory,
phonebook,
phar,
ph5,
pfd,
pec,
pdf,
payload,
path,
password,
papeeteonline,
pagina,
pages,
padasoft,
oxygen,
overflow vulnerability,
osticket,
osdate,
oscommerce,
optimized c,
openx,
openssl,
open,
opcode,
online,
onepound,
omnitec,
omegabill,
olonet,
object c,
nusoap,
numberformatter,
null bytes,
nuke,
novatek,
norinco,
niveldigital,
newsletter version,
newsletter administrator,
newsletter,
newsdettaglio,
newsdesc,
news script,
news php,
news item,
news,
new,
networld,
netvidade,
netstart,
name,
nagios,
nabernet,
mysqlnd,
mysql,
myphpnuke,
myldlinker,
mybusinessadmin,
mybb,
muzedon,
multiple buffer overflow,
multimedia,
multibyte character,
multibyte,
multi,
mrw,
mrcgiguy,
mops,
month,
monitor,
module,
modelbook,
model kits,
mode restriction,
mode,
mod,
mktba,
mkfifo,
mjb,
misc,
mini,
mime decode,
mike silverman,
midicart,
mevin,
metinfo,
methodologies,
metasploit,
memory usage,
memory corruption,
member profile,
member,
megavideo,
mediawiki,
mblogger,
may,
max,
maticmarket,
mateusz kocielski,
matchmaker,
mass mailer,
martin barbella,
mantisbt,
manager version,
manager v1,
manager pro,
manager plugin,
manager,
mambohelpdesk,
malicious users,
malformed,
makemedia,
mainick,
main,
mailers,
mailer,
mail,
loop,
login script,
login attempts,
login,
logger,
local resources,
local,
load,
llc,
live,
listing,
listevents,
listendifferent,
lionwiki,
linux security,
links,
link manager,
link directory,
link ads,
link,
lightopencms,
lightneasy,
license,
lfi,
lcg,
lava,
langchoice,
lab,
kreativity,
krazy,
koobi,
kolang,
knull,
knowledgetree,
knowledgebase,
kleinanzeigenmarkt,
keyword parameter,
kayako,
kategori,
justvisual,
jtl shop,
jtiny,
jportal,
journal,
joomla,
jokesite,
joke,
jobsite,
jobs,
jedit,
jce tech,
irealty,
iphone,
ip range,
inyourlife,
inventory,
intl,
interruption,
internet based,
interactive shell,
integer overflow,
integer,
instances,
install,
inputserialitemsfile,
input validation vulnerabilities,
input validation,
infotel,
information leak,
informacion,
indiacon,
inc news,
implementations,
imedia,
imap,
imanager,
images,
image processing,
image manager,
image host,
image,
ignition,
ideas factory,
icloudcenter,
ibrowser,
iboutique,
ibase,
hym,
hyip,
hunter,
http referer,
htmlentities,
html,
htb,
hotel booking system,
hosting directory,
hosting,
horoscopes,
home web,
home,
homap cms,
holocms,
hlstatsx,
hlstats,
hijacking,
hexjector,
help,
heap corruption,
heap,
header php,
header,
hastymail,
hashtables,
hash table,
hash,
hacks,
gunaysoft,
guestbook php,
guestbook,
grzegorz stachowiak,
gruppo,
group,
graphy,
grapheme,
granet,
gradient,
goran sql,
goran cross,
goran,
goo gallery,
goo,
glob,
gist,
getsymbol,
getpic,
getopt,
getarchivecomment,
gen,
gd extension,
gbook,
garde,
gamepage,
game id,
game,
gallarific,
fusion,
funnel web,
funnel,
funkgallery,
function php,
fulci,
friend,
fremens,
freenas,
free,
framework,
forum php,
forum 1,
forum,
format string bug,
format string,
format,
form php,
fns,
flaws,
flash chat,
flash,
fixed,
finweb,
filter,
file uploads,
file uploader,
file sharing system,
fasites,
faq,
family connections,
family,
false sense of security,
factory,
facebook,
extract,
extcalendar,
ext,
exploits,
exhaustive search,
exhaustion,
exec,
evento,
eurosito,
esupport,
estate,
esa,
error,
erotik,
eros,
eremetia,
entropy,
enthusiast,
engine,
encode,
employee timeclock,
empeng,
emlak,
elenco,
elements,
el mithak,
edgephp,
ecshop,
ecocms,
eclosion,
ecard,
e107,
e mall,
e mail,
dynpage,
dynamic program analysis,
dynamic php,
dutch book,
druckansicht,
dpconsulenze,
dpage,
downloadfile,
downloader,
download,
dowgroup,
dow,
dos vulnerability,
dork,
dompdf,
dolphin,
dokuwiki,
discovery,
directory version,
directory traversal,
directory pathnames,
directory listing,
director,
dev,
dettaglio,
detalhe,
detail,
design property,
design flaws,
design,
deltascripts,
dedacom,
decode,
dcms,
dbcms,
db connection,
datriks,
dataville,
datasouth,
database access,
database,
data gallery,
dan rosenberg,
d tekweb,
d link,
cultbooking,
cucina,
cubecart,
crypt,
cruxcms,
crs,
cron,
creso,
credentials,
creative content,
crawlability,
crackers,
cpassman,
coupon,
cotonti,
controller class,
contentpage,
content models,
content manager,
content management system,
content,
contact,
consulweb,
connections,
config,
conf,
concrete,
concern over safety,
concern,
concept,
component,
complete system,
communications design,
common,
command shell,
command execution,
command,
collision,
collections,
coherendz,
cmd,
clubpage,
clone,
clearsite,
clearbudget,
classifieds ads,
classifieds,
classified ads software,
classified,
classificados,
class,
cityadmin,
cid,
churchinfo,
chrome,
chezola,
checker,
chatlakturk,
chat,
cgcraft,
cc checker,
caucho technology,
catalogo,
cat id,
cat,
cart,
carfari,
car,
captcha,
candid view,
candid,
call time,
call for papers,
calendars,
calendar version,
c heap,
c format string,
bvcom,
buzlab,
business directory,
business,
build,
bug,
buffer overflow vulnerabilities,
bt4,
bsi,
bruteforcer,
brotherscripts,
breach,
boy,
botlu,
boomer,
bookmarks,
booking calendar,
booking,
book group,
board,
blogging,
blog,
blind,
bind,
bigthink,
big,
bible search,
bible,
bexfront,
better,
best real estate,
bbzl,
bbmedia,
bbcode,
battle,
bassanonet,
basic,
based buffer overflow,
base web,
base question,
base interface,
banner,
b classic,
automobile,
auto,
authentication system,
authentication mechanism,
authentication,
auracms,
auktionshaus,
auktion,
auction script,
auction forum,
auction,
atividades,
atacimo,
asp,
askme,
articolo,
article,
art studio,
art info,
array,
arduino,
ardeacore,
arcade,
arbitrary web,
arbitrary values,
arbitrary html,
arbitrary commands,
arbitrary command,
arbitrary,
apt webshop system,
apps,
application crash,
api,
aphpkb,
apc,
apboard,
ap 7,
answer,
announcements,
ani shell,
ani,
andy,
altogrado,
alternative,
alstrasoft,
alpha1,
alpha,
alibaba,
album,
akmed,
ajax,
affiliate script,
affiliate,
advertising software,
advanced,
advance,
administrator,
administrative privileges,
administrative password,
administrative,
admin index,
admin,
addon,
addiction,
addglob,
addcomment,
activecollab,
access control,
about,
ablespace,
a blog,
Support,
Software,
Related,
Pentesting,
Newbie,
Issues,
General,
BackTrack,
Area,
4images
Skip to page:
1
2
3
...
6
-
13:56
»
Packet Storm Security Exploits
This Metasploit module exploits a vulnerability found in WeBid version 1.0.2. By abusing the converter.php file, a malicious user can inject PHP code in the includes/currencies.php script without any authentication, which results in arbitrary code execution.
-
13:56
»
Packet Storm Security Recent Files
This Metasploit module exploits a vulnerability found in WeBid version 1.0.2. By abusing the converter.php file, a malicious user can inject PHP code in the includes/currencies.php script without any authentication, which results in arbitrary code execution.
-
13:56
»
Packet Storm Security Misc. Files
This Metasploit module exploits a vulnerability found in WeBid version 1.0.2. By abusing the converter.php file, a malicious user can inject PHP code in the includes/currencies.php script without any authentication, which results in arbitrary code execution.
-
13:29
»
Packet Storm Security Exploits
This Metasploit module exploits a vulnerability found in Dorn Content Management Script (CMS), version 1.4. By abusing the add_page.php file, the attacker can upload/add a new file (.php) to the /cms/pages/ directory without any authentication, which results in arbitrary code execution.
-
13:29
»
Packet Storm Security Recent Files
This Metasploit module exploits a vulnerability found in Dorn Content Management Script (CMS), version 1.4. By abusing the add_page.php file, the attacker can upload/add a new file (.php) to the /cms/pages/ directory without any authentication, which results in arbitrary code execution.
-
13:29
»
Packet Storm Security Misc. Files
This Metasploit module exploits a vulnerability found in Dorn Content Management Script (CMS), version 1.4. By abusing the add_page.php file, the attacker can upload/add a new file (.php) to the /cms/pages/ directory without any authentication, which results in arbitrary code execution.
-
-
19:44
»
Packet Storm Security Exploits
This Metasploit module exploits a vulnerability found in appRain's Content Management Framework (CMF), version 0.1.5 or less. By abusing the uploadify.php file, a malicious user can upload a file to the uploads/ directory without any authentication, which results in arbitrary code execution.
-
19:44
»
Packet Storm Security Recent Files
This Metasploit module exploits a vulnerability found in appRain's Content Management Framework (CMF), version 0.1.5 or less. By abusing the uploadify.php file, a malicious user can upload a file to the uploads/ directory without any authentication, which results in arbitrary code execution.
-
19:44
»
Packet Storm Security Misc. Files
This Metasploit module exploits a vulnerability found in appRain's Content Management Framework (CMF), version 0.1.5 or less. By abusing the uploadify.php file, a malicious user can upload a file to the uploads/ directory without any authentication, which results in arbitrary code execution.
-
-
14:47
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0570-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A flaw was found in the way the php-cgi executable processed command line arguments when running in CGI mode. A remote attacker could send a specially-crafted request to a PHP script that would result in the query string being parsed by php-cgi as command line options and arguments. This could lead to the disclosure of the script's source code or arbitrary code execution with the privileges of the PHP interpreter. Red Hat is aware that a public exploit for this issue is available that allows remote code execution in affected PHP CGI configurations. This flaw does not affect the default configuration using the PHP module for Apache httpd to handle PHP scripts.
-
14:47
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0570-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A flaw was found in the way the php-cgi executable processed command line arguments when running in CGI mode. A remote attacker could send a specially-crafted request to a PHP script that would result in the query string being parsed by php-cgi as command line options and arguments. This could lead to the disclosure of the script's source code or arbitrary code execution with the privileges of the PHP interpreter. Red Hat is aware that a public exploit for this issue is available that allows remote code execution in affected PHP CGI configurations. This flaw does not affect the default configuration using the PHP module for Apache httpd to handle PHP scripts.
-
-
14:02
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0569-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A flaw was found in the way the php-cgi executable processed command line arguments when running in CGI mode. A remote attacker could send a specially-crafted request to a PHP script that would result in the query string being parsed by php-cgi as command line options and arguments. This could lead to the disclosure of the script's source code or arbitrary code execution with the privileges of the PHP interpreter. Red Hat is aware that a public exploit for this issue is available that allows remote code execution in affected PHP CGI configurations. This flaw does not affect the default configuration using the PHP module for Apache httpd to handle PHP scripts.
-
14:02
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0569-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A flaw was found in the way the php-cgi executable processed command line arguments when running in CGI mode. A remote attacker could send a specially-crafted request to a PHP script that would result in the query string being parsed by php-cgi as command line options and arguments. This could lead to the disclosure of the script's source code or arbitrary code execution with the privileges of the PHP interpreter. Red Hat is aware that a public exploit for this issue is available that allows remote code execution in affected PHP CGI configurations. This flaw does not affect the default configuration using the PHP module for Apache httpd to handle PHP scripts.
-
14:02
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0568-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A flaw was found in the way the php-cgi executable processed command line arguments when running in CGI mode. A remote attacker could send a specially-crafted request to a PHP script that would result in the query string being parsed by php-cgi as command line options and arguments. This could lead to the disclosure of the script's source code or arbitrary code execution with the privileges of the PHP interpreter. Red Hat is aware that a public exploit for this issue is available that allows remote code execution in affected PHP CGI configurations. This flaw does not affect the default configuration in Red Hat Enterprise Linux 5 and 6 using the PHP module for Apache httpd to handle PHP scripts.
-
14:02
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0568-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A flaw was found in the way the php-cgi executable processed command line arguments when running in CGI mode. A remote attacker could send a specially-crafted request to a PHP script that would result in the query string being parsed by php-cgi as command line options and arguments. This could lead to the disclosure of the script's source code or arbitrary code execution with the privileges of the PHP interpreter. Red Hat is aware that a public exploit for this issue is available that allows remote code execution in affected PHP CGI configurations. This flaw does not affect the default configuration in Red Hat Enterprise Linux 5 and 6 using the PHP module for Apache httpd to handle PHP scripts.
-
14:02
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0568-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A flaw was found in the way the php-cgi executable processed command line arguments when running in CGI mode. A remote attacker could send a specially-crafted request to a PHP script that would result in the query string being parsed by php-cgi as command line options and arguments. This could lead to the disclosure of the script's source code or arbitrary code execution with the privileges of the PHP interpreter. Red Hat is aware that a public exploit for this issue is available that allows remote code execution in affected PHP CGI configurations. This flaw does not affect the default configuration in Red Hat Enterprise Linux 5 and 6 using the PHP module for Apache httpd to handle PHP scripts.
-
13:04
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0547-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A flaw was found in the way the php-cgi executable processed command line arguments when running in CGI mode. A remote attacker could send a specially-crafted request to a PHP script that would result in the query string being parsed by php-cgi as command line options and arguments. This could lead to the disclosure of the script's source code or arbitrary code execution with the privileges of the PHP interpreter. Red Hat is aware that a public exploit for this issue is available that allows remote code execution in affected PHP CGI configurations. This flaw does not affect the default configuration using the PHP module for Apache httpd to handle PHP scripts.
-
13:04
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0547-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A flaw was found in the way the php-cgi executable processed command line arguments when running in CGI mode. A remote attacker could send a specially-crafted request to a PHP script that would result in the query string being parsed by php-cgi as command line options and arguments. This could lead to the disclosure of the script's source code or arbitrary code execution with the privileges of the PHP interpreter. Red Hat is aware that a public exploit for this issue is available that allows remote code execution in affected PHP CGI configurations. This flaw does not affect the default configuration using the PHP module for Apache httpd to handle PHP scripts.
-
13:04
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0547-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A flaw was found in the way the php-cgi executable processed command line arguments when running in CGI mode. A remote attacker could send a specially-crafted request to a PHP script that would result in the query string being parsed by php-cgi as command line options and arguments. This could lead to the disclosure of the script's source code or arbitrary code execution with the privileges of the PHP interpreter. Red Hat is aware that a public exploit for this issue is available that allows remote code execution in affected PHP CGI configurations. This flaw does not affect the default configuration using the PHP module for Apache httpd to handle PHP scripts.
-
13:04
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0546-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A flaw was found in the way the php-cgi executable processed command line arguments when running in CGI mode. A remote attacker could send a specially-crafted request to a PHP script that would result in the query string being parsed by php-cgi as command line options and arguments. This could lead to the disclosure of the script's source code or arbitrary code execution with the privileges of the PHP interpreter. Red Hat is aware that a public exploit for this issue is available that allows remote code execution in affected PHP CGI configurations. This flaw does not affect the default configuration in Red Hat Enterprise Linux 5 and 6 using the PHP module for Apache httpd to handle PHP scripts.
-
13:04
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0546-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A flaw was found in the way the php-cgi executable processed command line arguments when running in CGI mode. A remote attacker could send a specially-crafted request to a PHP script that would result in the query string being parsed by php-cgi as command line options and arguments. This could lead to the disclosure of the script's source code or arbitrary code execution with the privileges of the PHP interpreter. Red Hat is aware that a public exploit for this issue is available that allows remote code execution in affected PHP CGI configurations. This flaw does not affect the default configuration in Red Hat Enterprise Linux 5 and 6 using the PHP module for Apache httpd to handle PHP scripts.
-
18:32
»
Packet Storm Security Exploits
When run as a CGI, PHP up to version 5.3.12 and 5.4.2 is vulnerable to an argument injection vulnerability. This Metasploit module takes advantage of the -d flag to set php.ini directives to achieve code execution. From the advisory: "if there is NO unescaped '=' in the query string, the string is split on '+' (encoded space) characters, urldecoded, passed to a function that escapes shell metacharacters (the "encoded in a system-defined manner" from the RFC) and then passes them to the CGI binary."
-
18:32
»
Packet Storm Security Misc. Files
When run as a CGI, PHP up to version 5.3.12 and 5.4.2 is vulnerable to an argument injection vulnerability. This Metasploit module takes advantage of the -d flag to set php.ini directives to achieve code execution. From the advisory: "if there is NO unescaped '=' in the query string, the string is split on '+' (encoded space) characters, urldecoded, passed to a function that escapes shell metacharacters (the "encoded in a system-defined manner" from the RFC) and then passes them to the CGI binary."
-
-
13:29
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-065 - The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service via a crafted application that uses a PDO driver for a fetch and then calls the session_start function, as demonstrated by a crash of the Apache HTTP Server. The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c. Insufficient validating of upload name leading to corrupted $_FILES indices. Various other issues have also been addressed.
-
13:29
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-065 - The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service via a crafted application that uses a PDO driver for a fetch and then calls the session_start function, as demonstrated by a crash of the Apache HTTP Server. The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c. Insufficient validating of upload name leading to corrupted $_FILES indices. Various other issues have also been addressed.
-
13:29
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-065 - The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service via a crafted application that uses a PDO driver for a fetch and then calls the session_start function, as demonstrated by a crash of the Apache HTTP Server. The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c. Insufficient validating of upload name leading to corrupted $_FILES indices. Various other issues have also been addressed.
-
-
17:08
»
Packet Storm Security Exploits
This Metasploit module exploits a vulnerability found on V-CMS's inline image upload feature. The problem is due to the inline_image_upload.php file not checking the file type before saving it on the web server. This allows any malicious user to upload a script (such as PHP) without authentication, and then execute it with a GET request. The issue is fixed in 1.1 by checking the extension name. By default, 1.1 only allows jpg, jpeg, png, gif, bmp, but it is still possible to upload a PHP file as one of those extension names, which may still be leveraged in an attack.
-
17:08
»
Packet Storm Security Recent Files
This Metasploit module exploits a vulnerability found on V-CMS's inline image upload feature. The problem is due to the inline_image_upload.php file not checking the file type before saving it on the web server. This allows any malicious user to upload a script (such as PHP) without authentication, and then execute it with a GET request. The issue is fixed in 1.1 by checking the extension name. By default, 1.1 only allows jpg, jpeg, png, gif, bmp, but it is still possible to upload a PHP file as one of those extension names, which may still be leveraged in an attack.
-
17:08
»
Packet Storm Security Misc. Files
This Metasploit module exploits a vulnerability found on V-CMS's inline image upload feature. The problem is due to the inline_image_upload.php file not checking the file type before saving it on the web server. This allows any malicious user to upload a script (such as PHP) without authentication, and then execute it with a GET request. The issue is fixed in 1.1 by checking the extension name. By default, 1.1 only allows jpg, jpeg, png, gif, bmp, but it is still possible to upload a PHP file as one of those extension names, which may still be leveraged in an attack.
-
-
12:11
»
Packet Storm Security Exploits
PHP versions 5.3.10 and 5.4.0 suffer from a cross site scripting vulnerability when display_errors is set to on and html_errors is set to on.
-
12:11
»
Packet Storm Security Misc. Files
PHP versions 5.3.10 and 5.4.0 suffer from a cross site scripting vulnerability when display_errors is set to on and html_errors is set to on.
-
19:49
»
Packet Storm Security Tools
Carbylamine PHP Encoder is a PHP Encoder for obfuscating/encoding PHP files so that antivirus detection signatures can be bypassed.
-
-
19:21
»
Packet Storm Security Advisories
PHP versions 5.2.0 through 5.2.17 suffers from an information disclosure and possible code execution vulnerability due to the filter_globals struct not being clean up during the shutdown stage.
-
19:21
»
Packet Storm Security Recent Files
PHP versions 5.2.0 through 5.2.17 suffers from an information disclosure and possible code execution vulnerability due to the filter_globals struct not being clean up during the shutdown stage.
-
19:21
»
Packet Storm Security Misc. Files
PHP versions 5.2.0 through 5.2.17 suffers from an information disclosure and possible code execution vulnerability due to the filter_globals struct not being clean up during the shutdown stage.
-
-
19:27
»
Packet Storm Security Exploits
This Metasploit module exploits an arbitrary PHP code execution vulnerability introduced as a backdoor into Horde 3.3.12 and Horde Groupware 1.2.10.
-
19:27
»
Packet Storm Security Recent Files
This Metasploit module exploits an arbitrary PHP code execution vulnerability introduced as a backdoor into Horde 3.3.12 and Horde Groupware 1.2.10.
-
19:27
»
Packet Storm Security Misc. Files
This Metasploit module exploits an arbitrary PHP code execution vulnerability introduced as a backdoor into Horde 3.3.12 and Horde Groupware 1.2.10.
-
-
23:46
»
Packet Storm Security Advisories
Ubuntu Security Notice 1358-1 - It was discovered that PHP computed hash values for form parameters without restricting the ability to trigger hash collisions predictably. This could allow a remote attacker to cause a denial of service by sending many crafted parameters. ATTENTION: this update changes previous PHP behavior by limiting the number of external input variables to 1000. This may be increased by adding a "max_input_vars" directive to the php.ini configuration file. See http://www.php.net/manual/en/info.configuration.php#ini.max-input-vars for more information. Various other issues were also addressed.
-
23:46
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1358-1 - It was discovered that PHP computed hash values for form parameters without restricting the ability to trigger hash collisions predictably. This could allow a remote attacker to cause a denial of service by sending many crafted parameters. ATTENTION: this update changes previous PHP behavior by limiting the number of external input variables to 1000. This may be increased by adding a "max_input_vars" directive to the php.ini configuration file. See http://www.php.net/manual/en/info.configuration.php#ini.max-input-vars for more information. Various other issues were also addressed.
-
23:46
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1358-1 - It was discovered that PHP computed hash values for form parameters without restricting the ability to trigger hash collisions predictably. This could allow a remote attacker to cause a denial of service by sending many crafted parameters. ATTENTION: this update changes previous PHP behavior by limiting the number of external input variables to 1000. This may be increased by adding a "max_input_vars" directive to the php.ini configuration file. See http://www.php.net/manual/en/info.configuration.php#ini.max-input-vars for more information. Various other issues were also addressed.
-
-
16:18
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0093-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. It was discovered that the fix for CVE-2011-4885 introduced an uninitialized memory use flaw. A remote attacker could send a specially-crafted HTTP request to cause the PHP interpreter to crash or, possibly, execute arbitrary code. All php users should upgrade to these updated packages, which contain a backported patch to resolve this issue. After installing the updated packages, the httpd daemon must be restarted for the update to take effect.
-
16:18
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0093-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. It was discovered that the fix for CVE-2011-4885 introduced an uninitialized memory use flaw. A remote attacker could send a specially-crafted HTTP request to cause the PHP interpreter to crash or, possibly, execute arbitrary code. All php users should upgrade to these updated packages, which contain a backported patch to resolve this issue. After installing the updated packages, the httpd daemon must be restarted for the update to take effect.
-
16:18
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0093-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. It was discovered that the fix for CVE-2011-4885 introduced an uninitialized memory use flaw. A remote attacker could send a specially-crafted HTTP request to cause the PHP interpreter to crash or, possibly, execute arbitrary code. All php users should upgrade to these updated packages, which contain a backported patch to resolve this issue. After installing the updated packages, the httpd daemon must be restarted for the update to take effect.
-
16:18
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0092-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. It was discovered that the fix for CVE-2011-4885 introduced an uninitialized memory use flaw. A remote attacker could send a specially- crafted HTTP request to cause the PHP interpreter to crash or, possibly, execute arbitrary code. All php53 users should upgrade to these updated packages, which contain a backported patch to resolve this issue. After installing the updated packages, the httpd daemon must be restarted for the update to take effect.
-
16:18
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0092-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. It was discovered that the fix for CVE-2011-4885 introduced an uninitialized memory use flaw. A remote attacker could send a specially- crafted HTTP request to cause the PHP interpreter to crash or, possibly, execute arbitrary code. All php53 users should upgrade to these updated packages, which contain a backported patch to resolve this issue. After installing the updated packages, the httpd daemon must be restarted for the update to take effect.
-
16:18
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0092-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. It was discovered that the fix for CVE-2011-4885 introduced an uninitialized memory use flaw. A remote attacker could send a specially- crafted HTTP request to cause the PHP interpreter to crash or, possibly, execute arbitrary code. All php53 users should upgrade to these updated packages, which contain a backported patch to resolve this issue. After installing the updated packages, the httpd daemon must be restarted for the update to take effect.
-
-
20:29
»
Packet Storm Security Exploits
This Metasploit module exploits a vulnerability in the 'proc_deutf()' function defined in /includes/functions_vbseocp_abstract.php in vBSEO versions 3.6.0 and below. User input passed through 'char_repl' POST parameter is not properly sanitized before being used in a call to preg_replace() function which uses the 'e' modifier. This can be exploited to inject and execute arbitrary code leveraging the PHP's complex curly syntax.
-
20:29
»
Packet Storm Security Recent Files
This Metasploit module exploits a vulnerability in the 'proc_deutf()' function defined in /includes/functions_vbseocp_abstract.php in vBSEO versions 3.6.0 and below. User input passed through 'char_repl' POST parameter is not properly sanitized before being used in a call to preg_replace() function which uses the 'e' modifier. This can be exploited to inject and execute arbitrary code leveraging the PHP's complex curly syntax.
-
20:29
»
Packet Storm Security Misc. Files
This Metasploit module exploits a vulnerability in the 'proc_deutf()' function defined in /includes/functions_vbseocp_abstract.php in vBSEO versions 3.6.0 and below. User input passed through 'char_repl' POST parameter is not properly sanitized before being used in a call to preg_replace() function which uses the 'e' modifier. This can be exploited to inject and execute arbitrary code leveraging the PHP's complex curly syntax.
-
11:21
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0071-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. It was found that the hashing routine used by PHP arrays was susceptible to predictable hash collisions. If an HTTP POST request to a PHP application contained many parameters whose names map to the same hash value, a large amount of CPU time would be consumed. This flaw has been mitigated by adding a new configuration directive, max_input_vars, that limits the maximum number of parameters processed per request. By default, max_input_vars is set to 1000.
-
11:21
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0071-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. It was found that the hashing routine used by PHP arrays was susceptible to predictable hash collisions. If an HTTP POST request to a PHP application contained many parameters whose names map to the same hash value, a large amount of CPU time would be consumed. This flaw has been mitigated by adding a new configuration directive, max_input_vars, that limits the maximum number of parameters processed per request. By default, max_input_vars is set to 1000.
-
11:21
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0071-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. It was found that the hashing routine used by PHP arrays was susceptible to predictable hash collisions. If an HTTP POST request to a PHP application contained many parameters whose names map to the same hash value, a large amount of CPU time would be consumed. This flaw has been mitigated by adding a new configuration directive, max_input_vars, that limits the maximum number of parameters processed per request. By default, max_input_vars is set to 1000.
-
3:11
»
Packet Storm Security Exploits
This Metasploit module exploits a vulnerability in the 'proc_deutf()' function defined in /includes/functions_vbseocp_abstract.php. User input passed through 'char_repl' POST parameter isn't properly sanitized before being used in a call to preg_replace() function which uses the 'e' modifier. This can be exploited to inject and execute arbitrary code leveraging the PHP's complex curly syntax.
-
3:11
»
Packet Storm Security Recent Files
This Metasploit module exploits a vulnerability in the 'proc_deutf()' function defined in /includes/functions_vbseocp_abstract.php. User input passed through 'char_repl' POST parameter isn't properly sanitized before being used in a call to preg_replace() function which uses the 'e' modifier. This can be exploited to inject and execute arbitrary code leveraging the PHP's complex curly syntax.
-
3:11
»
Packet Storm Security Misc. Files
This Metasploit module exploits a vulnerability in the 'proc_deutf()' function defined in /includes/functions_vbseocp_abstract.php. User input passed through 'char_repl' POST parameter isn't properly sanitized before being used in a call to preg_replace() function which uses the 'e' modifier. This can be exploited to inject and execute arbitrary code leveraging the PHP's complex curly syntax.
-
-
15:25
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0033-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. It was found that the hashing routine used by PHP arrays was susceptible to predictable hash collisions. If an HTTP POST request to a PHP application contained many parameters whose names map to the same hash value, a large amount of CPU time would be consumed. This flaw has been mitigated by adding a new configuration directive, max_input_vars, that limits the maximum number of parameters processed per request. By default, max_input_vars is set to 1000.
-
15:25
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0033-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. It was found that the hashing routine used by PHP arrays was susceptible to predictable hash collisions. If an HTTP POST request to a PHP application contained many parameters whose names map to the same hash value, a large amount of CPU time would be consumed. This flaw has been mitigated by adding a new configuration directive, max_input_vars, that limits the maximum number of parameters processed per request. By default, max_input_vars is set to 1000.
-
15:25
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0033-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. It was found that the hashing routine used by PHP arrays was susceptible to predictable hash collisions. If an HTTP POST request to a PHP application contained many parameters whose names map to the same hash value, a large amount of CPU time would be consumed. This flaw has been mitigated by adding a new configuration directive, max_input_vars, that limits the maximum number of parameters processed per request. By default, max_input_vars is set to 1000.
Skip to page:
1
2
3
...
6