slug: php

Explication

PHPはサーバーサイドで動くプログラミング言語で、Webサイトの裏側を作るのに広く使われています。 WordPress、Laravel、Drupalなど、世界中の多くのサイトの土台になっています。 セキュリティ脆弱性の文脈では「インジェクション系」(攻撃文字列を実行させる) や「ファイルアップロードの不備」が典型的な弱点として知られています。
📌 Exemple
2017年のEquifax事件 (1.4億人の個人情報流出) は、Apache StrutsというJavaライブラリの脆弱性が原因でしたが、同様にPHPアプリケーションでも脆弱性が悪用された事例は多数あります。

🔖 Étiquettes liées

🛡 Vulnérabilités associées 3,754

ID Titre
CVE-2017-16949 Téléversement de fichier dangereux dans wordpress (CVE-2017-16949)
CVE-2017-17645 Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
CVE-2017-17649 Injection de code dans readymade-video-sharing-script-project (CVE-2017-17649)
CVE-2017-17651 Injection SQL dans sqli (CVE-2017-17651)
CVE-2017-17727 Téléversement de fichier dangereux dans dedecms (CVE-2017-17727)
CVE-2017-17730 DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.
CVE-2017-17731 DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
CVE-2017-17733 Vulnérabilité dans maccms (CVE-2017-17733)
CVE-2017-17693 Vulnérabilité dans techno-portfolio-management-panel-project (CVE-2017-17693)
CVE-2017-17694 XSS (Cross-Site Scripting) dans techno-portfolio-management-panel-project (CVE-2017-17694)
CVE-2017-17695 Injection SQL dans sqli (CVE-2017-17695)
CVE-2017-17696 Divulgation d'information dans techno-portfolio-management-panel-project (CVE-2017-17696)
CVE-2017-17671 Traversée de chemin dans apache (CVE-2017-17671)
CVE-2017-17672 Désérialisation non sécurisée dans deserialization (CVE-2017-17672)
CVE-2017-17648 Injection SQL dans sqli (CVE-2017-17648)
CVE-2017-17638 Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
CVE-2017-17639 Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
CVE-2017-17640 Injection SQL dans sqli (CVE-2017-17640)
CVE-2017-17641 Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
CVE-2017-17613 Injection SQL dans sqli (CVE-2017-17613)
CVE-2017-17615 Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
CVE-2017-17617 Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
CVE-2017-17618 Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
CVE-2017-17622 Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
CVE-2017-17623 Injection SQL dans sqli (CVE-2017-17623)
CVE-2017-17624 Injection SQL dans sqli (CVE-2017-17624)
CVE-2017-17626 Injection SQL dans sqli (CVE-2017-17626)
CVE-2017-17627 Injection SQL dans sqli (CVE-2017-17627)
CVE-2017-17629 Injection SQL dans sqli (CVE-2017-17629)
CVE-2017-17631 Injection SQL dans sqli (CVE-2017-17631)

🍪 À propos des cookies

Nous utilisons des cookies pour conserver votre session, mémoriser la langue et améliorer le service.

En savoir plus →