<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:09:43 +0000</lastBuildDate>
    <item>
      <title>certa-2008-avi-593 — La version 5.2.7 de PHP récemment publiée présente une régression de
fonctionnalité des magic_quotes pouvant permettre…</title>
      <link>https://cve.radiocsirt.org/vuln/certa-2008-avi-593</link>
      <description>certa-2008-avi-593</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certa-2008-avi-593</guid>
    </item>
    <item>
      <title>EUVD-2026-130658</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-130658</link>
      <description>EUVD-2026-130658</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-130658</guid>
    </item>
    <item>
      <title>fkie_cve-2008-5814</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2008-5814</link>
      <description>&lt;p&gt;Cross-site scripting (XSS) vulnerability in PHP, possibly 5.2.7 and earlier, when display_errors is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: because of the lack of details, it is unclear whether this is related to CVE-2006-0208.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-site scripting (XSS) vulnerability in PHP, possibly 5.2.7 and earlier, when display_errors is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: because of the lack of details, it is unclear whether this is related to CVE-2006-0208.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2008-5814</guid>
    </item>
    <item>
      <title>GHSA-qmvx-3c3m-8hg9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qmvx-3c3m-8hg9</link>
      <description>&lt;p&gt;Cross-site scripting (XSS) vulnerability in PHP, possibly 5.2.7 and earlier, when display_errors is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: because of the lack of details, it is unclear whether this is related to CVE-2006-0208.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-site scripting (XSS) vulnerability in PHP, possibly 5.2.7 and earlier, when display_errors is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: because of the lack of details, it is unclear whether this is related to CVE-2006-0208.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qmvx-3c3m-8hg9</guid>
    </item>
    <item>
      <title>gsd-2008-5814</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2008-5814</link>
      <description>gsd-2008-5814</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2008-5814</guid>
    </item>
    <item>
      <title>jvndb-2008-000084</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2008-000084</link>
      <description>&lt;p&gt;PHP contains a cross-site scripting vulnerability.&#13;
&#13;
PHP is an open source scripting language that is especially suited for Web development. PHP contains a cross-site scripting vulnerability as it does not properly handle errors.&#13;
&#13;
Tomoki Sanaki of International Network Security, Inc. reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PHP contains a cross-site scripting vulnerability.&#13;
&#13;
PHP is an open source scripting language that is especially suited for Web development. PHP contains a cross-site scripting vulnerability as it does not properly handle errors.&#13;
&#13;
Tomoki Sanaki of International Network Security, Inc. reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2008-000084</guid>
    </item>
    <item>
      <title>RHSA-2009:0338 — Red Hat Security Advisory: php security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2009:0338</link>
      <description>&lt;p&gt;php: buffer overflow in the imageloadfont function in gd extension php: FastCGI module DoS via multiple dots preceding the extension php: libgd imagerotate() array index error memory disclosure php: Heap-based buffer overflow in the mbstring extension via crafted string containing a HTML entity (arb code execution) php: XSS via PHP error messages PHP mbstring.func_overload web server denial of service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;php: buffer overflow in the imageloadfont function in gd extension php: FastCGI module DoS via multiple dots preceding the extension php: libgd imagerotate() array index error memory disclosure php: Heap-based buffer overflow in the mbstring extension via crafted string containing a HTML entity (arb code execution) php: XSS via PHP error messages PHP mbstring.func_overload web server denial of service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2009:0338</guid>
    </item>
  </channel>
</rss>
