Vulnerabilities (CVE)

Filtered by vendor Php Subscribe
Filtered by product Php
Total 747 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0108 2 Mandrakesoft, Php 2 Mandrake Linux, Php 2026-06-16 5.0 MEDIUM N/A
PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.
CVE-2000-0967 1 Php 1 Php 2026-06-16 10.0 HIGH N/A
PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.
CVE-2000-0860 1 Php 1 Php 2026-06-16 5.0 MEDIUM N/A
The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables.
CVE-2000-0059 1 Php 1 Php 2026-06-16 10.0 HIGH N/A
PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.
CVE-1999-0238 1 Php 1 Php 2026-06-16 10.0 HIGH N/A
php.cgi allows attackers to read any file on the system.
CVE-1999-0068 1 Php 1 Php 2026-06-16 7.5 HIGH N/A
CGI PHP mylog script allows an attacker to read any file on the target server.
CVE-1999-0058 1 Php 1 Php 2026-06-16 7.5 HIGH N/A
Buffer overflow in PHP cgi program, php.cgi allows shell access.