Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHP Symbolic Link Open_Basedir Bypass Vulnerability

PHP is prone to an 'open_basedir' restriction-bypass vulnerability. Successful exploits could allow an attacker to access sensitive information or to write files in unauthorized locations.

This vulnerability would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code; in such cases, the 'open_basedir' restriction is expected to isolate users from each other.

This issue is reported to affect PHP versions 4 and 5.







 

Privacy Statement
Copyright 2009, SecurityFocus