296,746
Total vulnerabilities in the database
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.
| Software | From | Fixed in |
|---|---|---|
| php / php | - | 5.2.6 |
| fedoraproject / fedora | 9 | 9.x |
| fedoraproject / fedora | 8 | 8.x |
| canonical / ubuntu_linux | 7.04 | 7.04.x |
| canonical / ubuntu_linux | 7.10 | 7.10.x |
| canonical / ubuntu_linux | 8.04 | 8.04.x |
| canonical / ubuntu_linux | 6.06 | 6.06.x |
| apple / mac_os_x_server | - | 10.5.4 |
| apple / mac_os_x | - | 10.5.4 |