Exploitdb Exploits

1,269 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-1584 EXPLOITDB php VERIFIED
PHP 5.2.0 - RCE
Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by passing an all-whitespace string to this function, which causes it to write '\0' characters in whitespace that precedes the string.
by Stefan Esser
CVE-2007-1635 EXPLOITDB php VERIFIED
Net Portal Dynamic System <5.10 - Code Injection
Static code injection vulnerability in admin/settings.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote authenticated users to inject arbitrary PHP code via the xtop parameter in a "ConfigSave" op to admin.php, which can later be accessed via a "Configure" op to admin.php.
by DarkFig
CVE-2007-1612 EXPLOITDB php VERIFIED
Katalog Plyt Audio < 1.0 - SQL Injection
SQL injection vulnerability in index.php in Katalog Plyt Audio 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the kolumna parameter.
by Kacper
EIP-2026-111212 EXPLOITDB php VERIFIED
phpStats 0.1.9 - 'PHP-Stats-options.php' Remote Code Execution
by rgod
CVE-2006-7173 EXPLOITDB php VERIFIED
PHP-Stats <0.1.9.1b - Code Injection
Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP code via a crafted option_new[report_w_day] parameter in a preferenze action, which can be later accessed via option/php-stats-options.php.
by rgod
EIP-2026-111213 EXPLOITDB php VERIFIED
phpStats 0.1.9 - Multiple SQL Injections
by rgod
CVE-2006-7172 EXPLOITDB php VERIFIED
Php-stats < 0.1.9.1b - SQL Injection
Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers to execute arbitrary code via a leading dotted-quad IP address string in the (1) PC-REMOTE-ADDR HTTP header, which is inserted into $_SERVER['HTTP_PC_REMOTE_ADDR'], or (2) ip parameter.
by rgod
CVE-2006-7172 EXPLOITDB php VERIFIED
Php-stats < 0.1.9.1b - SQL Injection
Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers to execute arbitrary code via a leading dotted-quad IP address string in the (1) PC-REMOTE-ADDR HTTP header, which is inserted into $_SERVER['HTTP_PC_REMOTE_ADDR'], or (2) ip parameter.
by rgod
CVE-2007-1484 EXPLOITDB php VERIFIED
PHP <4.4.6 & <5.2.1 - Code Injection
The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, which triggers memory corruption and allows local users to bypass safe_mode and execute arbitrary code via a certain unset operation after array_user_key_compare has been called.
by Stefan Esser
CVE-2007-1475 EXPLOITDB php VERIFIED
Php < 4.4.6 - Buffer Overflow
Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-dependent attackers to execute arbitrary code via a long argument.
by rgod
CVE-2007-1521 EXPLOITDB php VERIFIED
PHP <4.4.7, <5.2.2 - Use After Free
Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a memory limit violation.
by Stefan Esser
CVE-2007-1522 EXPLOITDB php VERIFIED
PHP 5.2.0-5.2.1 - Use After Free
Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which calls the session identifier generator with an improper environment, leading to code execution when the generator is interrupted, as demonstrated by triggering a memory limit violation or certain PHP errors.
by Stefan Esser
CVE-2007-1453 EXPLOITDB php VERIFIED
PHP <5.2.0 - RCE
Buffer underflow in the PHP_FILTER_TRIM_DEFAULT macro in the filtering extension (ext/filter) in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by calling filter_var with certain modes such as FILTER_VALIDATE_INT, which causes filter to write a null byte in whitespace that precedes the buffer.
by Stefan Esser
CVE-2007-1584 EXPLOITDB php VERIFIED
PHP 5.2.0 - RCE
Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by passing an all-whitespace string to this function, which causes it to write '\0' characters in whitespace that precedes the string.
by Stefan Esser
CVE-2007-1493 EXPLOITDB php VERIFIED
NukeSentinel <2.5.06 - SQL Injection
nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, which allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, due to an incomplete patch for CVE-2007-1172.
by DarkFig
CVE-2007-1452 EXPLOITDB php VERIFIED
PHP <5.2.0 - XSS
The FDF support (ext/fdf) in PHP 5.2.0 and earlier does not implement the input filtering hooks for ext/filter, which allows remote attackers to bypass web site filters via an application/vnd.fdf formatted POST.
by Stefan Esser
CVE-2007-1413 EXPLOITDB php VERIFIED
Php < 5.2.3 - Memory Corruption
Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably other PHP 4 versions, allows context-dependent attackers to execute arbitrary code via a long value in the third argument (object id).
by rgod
CVE-2007-1412 EXPLOITDB php VERIFIED
PHP 4.4.6 - Info Disclosure
The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensitive information (script source code) via a long string in the second argument.
by rgod
CVE-2007-1399 EXPLOITDB CRITICAL php VERIFIED
Php < 1.8.4 - Buffer Overflow
Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arbitrary code via a long zip:// URL, as demonstrated by actively triggering URL access from a remote PHP interpreter via avatar upload or blog pingback.
by Stefan Esser
CVSS 9.8
CVE-2007-1401 EXPLOITDB php VERIFIED
Php - Buffer Overflow
Buffer overflow in the crack extension (CrackLib), as bundled with PHP 4.4.6 and other versions before 5.0.0, might allow local users to gain privileges via a long argument to the crack_opendict function.
by rgod
CVE-2007-1382 EXPLOITDB php VERIFIED
PHP COM - RCE
The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demonstrated by using the Run method of this object to execute cmd.exe, which bypasses PHP's safe mode.
by anonymous
CVE-2007-1375 EXPLOITDB php VERIFIED
PHP <5.2.1 - Memory Corruption
Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sensitive memory via a large value in the length argument, a different vulnerability than CVE-2006-1991.
by Stefan Esser
CVE-2007-1376 EXPLOITDB php VERIFIED
PHP <4.4.5, <5.2.1 - Memory Corruption
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which allows context-dependent attackers to read and write arbitrary memory locations via arguments associated with an inappropriate resource, as demonstrated by a GD Image resource.
by Stefan Esser
CVE-2007-1376 EXPLOITDB php VERIFIED
PHP <4.4.5, <5.2.1 - Memory Corruption
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which allows context-dependent attackers to read and write arbitrary memory locations via arguments associated with an inappropriate resource, as demonstrated by a GD Image resource.
by Stefan Esser
CVE-2007-1411 EXPLOITDB php VERIFIED
Php < 4.4.6 - Buffer Overflow
Buffer overflow in PHP 4.4.6 and earlier, and unspecified PHP 5 versions, allows local and possibly remote attackers to execute arbitrary code via long server name arguments to the (1) mssql_connect and (2) mssql_pconnect functions.
by rgod