Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: php create_function commond injection vulnerability Sep 29 2008 05:14PM
Steven M. Christey (coley mitre org)

There are two main takeaways from this advisory:

1) PHP application programmers can and will misuse this function
(CVE-2008-4096, CVE-2007-5423), but most PHP code auditors probably
don't check for it yet. So it's good for awareness.

2) Any language that has an equivalent capability for cr...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus