Total vulnerabilities in the database
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.
Software | From | Fixed in |
---|---|---|
php / php | - | 5.2.6 |
fedoraproject / fedora | 9 | 9.x |
fedoraproject / fedora | 8 | 8.x |
canonical / ubuntu_linux | 7.04 | 7.04.x |
canonical / ubuntu_linux | 7.10 | 7.10.x |
canonical / ubuntu_linux | 8.04 | 8.04.x |
canonical / ubuntu_linux | 6.06 | 6.06.x |
apple / mac_os_x_server | - | 10.5.4 |
apple / mac_os_x | - | 10.5.4 |