PHP Vulnerabilities
The following list includes some of the most critical PHP vulnerabilities known to the security community. In any case you find that there is anything missing in this list, please let us know and we will update it as soon as possible.
- HP-UX Running Apache with PHP Multiple Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP-Calendar Cross Site Scripting Vulnerabilities
- PHP Multipart/Form-data Denial of Service Attack
- PHP gd Library imageRotate() Function Information Leak Vulnerability
- PHP mbstring Buffer Overflow Vulnerability
- PHP APC Vulnerable to Local Attacks
- PHP SAPI php_getuid() Overload
- PHP dba_replace() Arbitrary File Destruction
- Cross-Site Scripting Filter Evasion in Various Frameworks / Applications
- PHP GENERATE_SEED() Weak Random Number Seed Vulnerability
- PHP Multibyte Shell Command Escaping Bypass Vulnerability
- PHP cURL Safe_mode Bypass
- Apache HTTP Server 413 Error Page XSS
- PHP Win32std Extension safe_mode/disable_functions Protections Bypass
- PHP chunk_split() Integer Overflow
- PHP wbmp File Handling Integer Overflow
- PHP zip:// URL Wrapper Buffer Overflow Vulnerability
- PHP ext/filter Space Trimming Buffer Underflow Vulnerability
- PHP ext/filter HTML Tag Stripping Bypass Vulnerability
- PHP5 Post Filter Bypass (ext filter FDF, Exploit)
- PHP4 Local Buffer Overflow (mssql_connect, mssql_pconnect)
- PHP4 phpinfo() XSS Vulnerability (Reintroduced)
- PHP WDDX Session Deserialization Information Leak Vulnerability
- Dotdeb PHP Email Header Injection Vulnerability
- PHP unserialize() Array Creation Integer Overflow (PoC)
- PHP unserialize() Array Creation Integer Overflow
- PHP 5.1.6 / 4.4.4 Critical php_admin* Bypass by ini_restore()
- PHP File-Upload GLOBALS Overwrite Vulnerability
- PHP Local Buffer Underflow
- PHP ip2long() Function Circumvention (miniBB)
- Ultimate PHP Board Multiple Vulnerabilities
- Ultimate PHP Board Multiple Vulnerabilities (Exploit)
- cURL Safe Mode Bypass PHP
- Invision Power Board Army System Mod SQL Injection Exploit
- PHP Globals Filtering Bypass
- PHP for Windows create_named_pipe Buffer Overflow
- PHP Fusion CMS Multiple Vulnerabilities (subheader.php, options.php)
- PHP Multiple Vulnerabilities (File Upload, parse_str() register_global bypassing, phpinfo XSS)
- PHP-Fusion msg_send SQL Injection
- PHP-Fusion Accessible Database Backups Download (Exploit)
- PHP Calendar Buffer Overflow
- Ultimate PHP Board Password Hash Decryptor
- PortailPHP SQL Injection (Exploit)
- PHP-Nuke HTTP Response Splitting
- PHP-Nuke Blind SQL Injection (Download Module)
- SPHPBlog Multiple Vulnerabilities (Exploit)
- PHP getimagesize() Multiple DoS Vulnerabilities
- Squirrelcart PHP Shopping Cart SQL Injection
- Multiple Vulnerabilities in PHP (Information Discloser, File Access, Negative Reference, Integer Handeling Bug, Buffer Overflow, Directory Traversal, Arbitrary File Upload)
- Cross Site Scripting Vulnerability In PHP-Fusion
- Multiple Vulnerabilities in PHP-Nuke (db.php, index.php, Downloads, Web_Links)
- PHP-Nuke POST Method Admin Variable Privilege Escalation
- Simple PHP Blog Directory Traversal
- Jacks FormMail.php Remote File Access Vulnerability
- PHP openlog() Buffer Overflow
- PHP Input Validation Vulnerabilities (addslashes, Windows Only)
- PHP Shmop Write of Arbitrary Memory (Exploit)
- Multiple Vulnerabilities within PHP 4/5 (pack, unpack, safe_mode_exec_dir, safe_mode, realpath, unserialize)
- PHP-Fusion SQL Injection (index.php)
- PHP memory_limit Exploit Code
- phpBugTracker bug.php SQL Injection
- PHP Array Heap Content Disclosure
- PHP-Nuke XSS Vulnerabilities Through AddMsg And Newsletter Features
- PHP-Nuke ViewAdmin Cross Site Scripting Bug
- PHP-FUSION Various Vulnerabilities
- PHP-Nuke Multiple Vulnerabilities (Journal, WebLinks And Statistics Module)
- PHPNuke Multiple Vulnerabilities in Search Module (Comments Search)
- PHP memory_limit Remote Vulnerability
- PHP strip_tags() bypass vulnerability
- PHP-Nuke Multiple Vulnerabilities (Reviews/Encyclopedia/FAQ Modules)
- PHP-Nuke Inadequate Security Give Rise to a Variety of Attack Methods
- PHP Win32 escapeshellcmd() and escapeshellarg() Input Validation Vulnerability
- XSS and Path Disclosure in Network Query Tool
- Protector System Multiple Vulnerabilities
- PhotoPost PHP Pro Multiple Vulnerabilities
- PHP-Nuke Cross Site Scripting Vulnerability (News, Reviews)
- Photopost PHP Pro SQL Injection Vulnerability
- PHP-Nuke \cid\ SQL Injection
- AutoRank PHP SQL Injection Vulnerabilities
- Aardvark Topsites Multiple Vulnerabilities
- PHP-Nuke WebMail Command Execution Vulnerability (Mailattach)
- UPB Discussion Board/Web-Site Takeover
- PHP-Proxima Remote File Access Vulnerability
- PHP-Nuke \News\ Module SQL Injection
- CGI SAPI Security Vulnerability
- Mambo PHP-Portal Vulnerability (XSS and Command Execution)
- PHPNuke Path Disclosure (Your_Account)
- PHP-Nuke mail CRLF Injection Vulnerabilities
- Networking Utils PHP Allows Execution of Arbitrary code.
- Denial of Service Vulnerability in Xeneo Web Server
- IMG Attack in The News 6 CMS Vulnerabilities
- Multiple Web Security Holes (TightAuction, PY-Membres, upb PB, MidiCart PHP, Pphlogger)
- XSS Bug in php(Reactor)
- PHP Debugging Function Script Injection Vulnerability
- PHP Source Injection in phpWebSite
- PHP fopen() CRLF Injection
- PHP Allows Bypassing of safe_mode And Injecting ASCII Control Chars With mail()
- PHPNuke Private Messaging Module Allows Compromising of Administrator Accounts
- Additional Details Released on PHP Security Vulnerability in Multipart FORM Data Handling
- PHP Security Vulnerability in Multipart FORM Data Handling
- Cross-Site Scripting Vulnerability in PHP Classifieds
- PHP Source Injection in PHP-Address
- PHP-Survey Global.INC Information Disclosure Vulnerability
- Posix_getpw* Ignores Safe_mode and Open_basedir Settings