slug: php

Explication

PHPはサーバーサイドで動くプログラミング言語で、Webサイトの裏側を作るのに広く使われています。 WordPress、Laravel、Drupalなど、世界中の多くのサイトの土台になっています。 セキュリティ脆弱性の文脈では「インジェクション系」(攻撃文字列を実行させる) や「ファイルアップロードの不備」が典型的な弱点として知られています。
📌 Exemple
2017年のEquifax事件 (1.4億人の個人情報流出) は、Apache StrutsというJavaライブラリの脆弱性が原因でしたが、同様にPHPアプリケーションでも脆弱性が悪用された事例は多数あります。

🔖 Étiquettes liées

🛡 Vulnérabilités associées 3,763

ID Titre
CVE-2017-15987 Injection SQL dans sqli (CVE-2017-15987)
CVE-2017-15988 Injection SQL dans sqli (CVE-2017-15988)
CVE-2017-15989 Injection SQL dans sqli (CVE-2017-15989)
CVE-2017-15990 Téléversement de fichier dangereux dans savsofteproducts (CVE-2017-15990)
CVE-2017-15991 Injection SQL dans sqli (CVE-2017-15991)
CVE-2017-15992 Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.
CVE-2017-15993 Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.
CVE-2017-16230 XSS (Cross-Site Scripting) dans typecho (CVE-2017-16230)
CVE-2017-7411 Injection de code dans enalean (CVE-2017-7411)
CVE-2017-16000 Injection SQL dans sqli (CVE-2017-16000)
CVE-2017-15975 Injection SQL dans sqli (CVE-2017-15975)
CVE-2017-15976 Injection SQL dans sqli (CVE-2017-15976)
CVE-2017-15956 Vulnérabilité dans converto-video-downloader-converter-project (CVE-2017-15956)
CVE-2017-15957 Téléversement de fichier dangereux dans ingenious-school-management-system-project (CVE-2017-15957)
CVE-2017-15958 D-Park Pro Domain Parking Script 1.0 allows SQL Injection via the username to admin/loginform.php.
CVE-2017-15960 Injection SQL dans sqli (CVE-2017-15960)
CVE-2017-15961 iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.
CVE-2017-15963 Injection SQL dans sqli (CVE-2017-15963)
CVE-2017-15966 Injection SQL dans sqli (CVE-2017-15966)
CVE-2017-15968 MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.
CVE-2017-15970 Injection SQL dans sqli (CVE-2017-15970)
CVE-2017-15971 Injection SQL dans sqli (CVE-2017-15971)
CVE-2017-15972 Injection SQL dans sqli (CVE-2017-15972)
CVE-2017-15973 Injection SQL dans sqli (CVE-2017-15973)
CVE-2017-15974 tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.
CVE-2017-15946 Injection SQL dans sqli (CVE-2017-15946)
CVE-2017-15949 Injection SQL dans sqli (CVE-2017-15949)
CVE-2017-15935 Injection de code dans artica (CVE-2017-15935)
CVE-2017-15933 Injection SQL dans sqli (CVE-2017-15933)
CVE-2012-4378 XSS (Cross-Site Scripting) dans mediawiki (CVE-2012-4378)

🍪 À propos des cookies

Nous utilisons des cookies pour conserver votre session, mémoriser la langue et améliorer le service.

En savoir plus →