Stefan Esser
61 exploits
Active since Dec 2002
PHP 4.x-5.0.0RC3 - XSS
PHP 4 < 4.4.5 and 5 < 5.2.1 - Buffer Overflow in imap_mail_compose
PHP 4.0.0-4.4.6 & 5.0.0-5.2.1 - Code Injection
PHP 5.2.0 - Buffer Underflow in PHP_FILTER_TRIM_DEFAULT Macro
PHP 4.0.0-4.4.6 and 5.0.0-5.2.1 - CRLF Injection via Mail Function Header Parameters
PHP 4.x-4.4.7 and 5.x-5.2.3 - Session Cookie Attribute Injection via Special Characters
PHP 5.3.0-5.3.2 - Denial of Service via Negative Chunk Size in HTTP Chunked Encoding Decoder
CVSS 9.8
PHP 5.3 - Format String Vulnerability in phar Extension
PHP < 4.4.4 - Remote Code Execution via Long String to unserialize Function
Apple Mac OSX 10.10 - 'DYLD_PRINT_TO_FILE' Local Privilege Escalation
PHP 5.2.0 - Buffer Underflow via Header Function
PHP 5.2.0 - Buffer Underflow via Header Function
PHP < 4.4.4 - Remote Code Execution via Long String to unserialize Function
PHP 4.4.3-4.4.6 - Cross-Site Scripting via phpinfo GET POST or COOKIE Array Values
PHP <= 5.2.0 - Filter Bypass via FDF Formatted POST
ModSecurity <= 2.1.0 - Request Rule Bypass via ASCIIZ Byte in POST Data
PHP 5.2.1 - Heap Memory Disclosure via Serialized Data Input
PHP - Buffer Overflow in wddx_deserialize via Malformed STRING Element
PHP 4 - Remote Code Execution via 16-bit Reference Counter Overflow
CVSS 9.8
PHP < 5.2.1 - Memory Read via substr_compare Length Argument
PHP <4.4.5, <5.2.1 - Info Disclosure
PHP <5.2.1 & <4.4.5 - Info Disclosure
CVS <= 1.11.4 - Double Free via Malformed Directory Request
PHP 4 <4.4.5, PHP 5 <5.2.1 - Code Injection
PHP <4.4.5, <5.2.1 - Memory Corruption