Php Exploits

1,332 exploits tracked across all sources.

Sort: Activity Stars
CVE-2009-1516 EXPLOITDB php VERIFIED
IceWarp Merak Mail Server 9.4.1 - Stack-Based Buffer Overflow via Base64FileEncode Method
Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependent attackers to execute arbitrary code via a large value in the second argument to the Base64FileEncode method, as possibly demonstrated by a web application that accepts untrusted input for this method.
by Nine:Situations:Group
EIP-2026-109128 EXPLOITDB php VERIFIED
LightBlog 9.9.2 - 'register.php' Remote Code Execution
by EgiX
EIP-2026-106509 EXPLOITDB php VERIFIED
Dokeos Lms 1.8.5 - 'whoisonline.php' PHP Code Injection
by EgiX
EIP-2026-107369 EXPLOITDB php VERIFIED
Geeklog 1.5.2 - 'usersettings.php' SQL Injection
by Nine:Situations:Group::bookoo
EIP-2026-107367 EXPLOITDB php VERIFIED
Geeklog 1.5.2 - 'savepreferences()/*blocks[]' SQL Injection
by Nine:Situations:Group
EIP-2026-118592 EXPLOITDB php VERIFIED
FTPDMIN 0.96 (Windows XP SP3) - 'RNFR' Remote Buffer Overflow
by surfista
EIP-2026-104702 EXPLOITDB php VERIFIED
PHP 5.2.9 cURL - 'Safe_mode' / 'open_basedir' Restriction Bypass
by Maksymilian Arciemowicz
EIP-2026-107368 EXPLOITDB php VERIFIED
Geeklog 1.5.2 - 'SEC_authenticate()' SQL Injection
by Nine:Situations:Group
EIP-2026-109064 EXPLOITDB php VERIFIED
Lanius CMS 0.5.2 - Arbitrary File Upload
by EgiX
CVE-2009-1282 EXPLOITDB php VERIFIED
glFusion <= 1.1.2 - SQL Injection via glf_session Cookie Parameter
SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the glf_session cookie parameter.
by Nine:Situations:Group
CVE-2009-1283 EXPLOITDB php VERIFIED
glFusion < 1.1.3 - Unauthenticated Privilege Escalation via Password Hash Cookie
glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privileges by obtaining the hash and using it in the glf_password cookie, aka "User Masquerading." NOTE: this can be leveraged with a separate SQL injection vulnerability to steal hashes.
by Nine:Situations:Group
CVE-2009-1226 EXPLOITDB php VERIFIED
Podcast Generator <= 1.1 - Unauthenticated Arbitrary File Deletion via Admin Delete Endpoint
core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter.
by BlackHawk
CVE-2009-1230 EXPLOITDB php VERIFIED
podcast_generator <= 1.1 - Authenticated PHP Code Injection via Recent Parameter
Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter in a config change action.
by BlackHawk
CVE-2009-1209 EXPLOITDB php VERIFIED
W3C Amaya Web Browser 11.1 - Remote Code Execution via Long Defer Attribute in Script Tag
Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script tag with a long defer attribute.
by Alfons Luja
CVE-2009-4796 EXPLOITDB php VERIFIED
glFusion <= 1.1.2 - SQL Injection via Order and Direction Parameters
Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in glFusion 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) order and (2) direction parameters to search.php.
by Nine:Situations:Group
EIP-2026-111084 EXPLOITDB php VERIFIED
PHPizabi 0.848b C1 HFP1-3 - Arbitrary File Upload
by EgiX
CVE-2008-6842 EXPLOITDB php VERIFIED
Pluck 4.6.1 - Path Traversal via Post Parameter
Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the post parameter.
by Alfons Luja
EIP-2026-111085 EXPLOITDB php VERIFIED
PHPizabi 0.848b C1 HFP1-3 - Remote Command Execution
by YOUCODE
CVE-2009-1068 EXPLOITDB php VERIFIED
BS.Player <=2.34 Build 980 - Stack-based Buffer Overflow via Long Hostname in .bsl Playlist File
Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long hostname in a .bsl playlist file.
by Nine:Situations:Group
CVE-2009-1039 EXPLOITDB php VERIFIED
CDex 1.70b2 - Remote Code Execution via Crafted Ogg Vorbis Info Header
Buffer overflow in CDex 1.70b2 allows remote attackers to execute arbitrary code via a crafted Info header in an Ogg Vorbis (.ogg) file.
by Nine:Situations:Group
EIP-2026-108374 EXPLOITDB php VERIFIED
Joomla! Component com_iJoomla_archive - Blind SQL Injection
by Stack
EIP-2026-108328 EXPLOITDB php VERIFIED
Joomla! Component com_digistore - 'pid' Blind SQL Injection
by InjEctOr5
CVE-2008-6178 EXPLOITDB php VERIFIED
FCKeditor 2.2 - Remote Code Execution via ZIP File Upload
Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4 CMS, Nuke ET, and other products, allows remote attackers to execute arbitrary code by creating a file with PHP sequences preceded by a ZIP header, uploading this file via a FileUpload action with the application/zip content type, and then accessing this file via a direct request to the file in UserFiles/File/, probably a related issue to CVE-2005-4094. NOTE: some of these details are obtained from third party information.
by Sp3shial
CVE-2009-0528 EXPLOITDB php VERIFIED
Rhadrix If-CMS <2.07 - SQL Injection
SQL injection vulnerability in frame.php in Rhadrix If-CMS 2.07 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by darkjoker
CVE-2009-0446 EXPLOITDB php VERIFIED
WEBalbum 2.4b - SQL Injection via photo.php id Parameter
SQL injection vulnerability in photo.php in WEBalbum 2.4b allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Mehmet Ince