Language11594+ CVE indexed

CVE PHP

All CVE vulnerabilities for PHP — the server-side scripting language powering 78% of the web.

13HIGH
7MEDIUM

Latest PHP CVEs

Source: NIST NVD — updated every 6h

See all 11594
CVE-1999-0058
HIGH7.5

Buffer overflow in PHP cgi program, php.cgi allows shell access.

CVE-1999-0238
HIGH10

php.cgi allows attackers to read any file on the system.

CVE-1999-0346
MEDIUM5

CGI PHP mlog script allows an attacker to read any file on the target server.

CVE-1999-0068
HIGH7.5

CGI PHP mylog script allows an attacker to read any file on the target server.

CVE-2000-0059
HIGH10

PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.

CVE-2000-0745
HIGH7.5

admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter.

CVE-2000-0860
MEDIUM5

The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables.

CVE-2000-0919
MEDIUM5

Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.

CVE-2000-0967
HIGH10

PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.

CVE-2000-1230
MEDIUM5

Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to "boogieman".

CVE-2000-1166
HIGH7.5

Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program.

CVE-2001-1385
MEDIUM5

The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.

CVE-2001-1357
HIGH7.5

Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.

CVE-2001-1358
HIGH7.2

Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library file in the L (localization) parameter.

CVE-2001-1468
HIGH7.5

PHP remote file inclusion vulnerability in checklogin.php in phpSecurePages 0.24 and earlier allows remote attackers to execute arbitrary PHP code by modifying the cfgProgDir parameter to reference a URL on a remote web server that contains the code.

CVE-2001-0042
MEDIUM5

PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.

CVE-2001-0043
HIGH10

phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info parameter of the phpgw.inc.php program.

CVE-2001-0088
HIGH7.5

common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog.

CVE-2001-0108
MEDIUM5

PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.

CVE-2001-0292
HIGH7.5

PHP-Nuke 4.4.1a allows remote attackers to modify a user's email address and obtain the password by guessing the user id (UID) and calling user.php with the saveuser operator.

Monitor PHP automatically

Add PHP to your asset inventory and receive an email alert the moment a new CVE is published. 7-day Enterprise trial, no credit card required.

Start free trial

No credit card · Cancel anytime