Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Zend Platform PHP.INI File Modification Vulnerability

The Zend Platform is prone to an issue that may let local attackers modify the PHP configuration file ('php.ini'). This issue occurs because the application is installed with an 'ini_modifier' program that may be executed by local users and will bypass the authentication that is required by the application to change the configuration file.

An attacker could add a malicious PHP extension to the configuration or otherwise tamper with PHP configuration directives. A successful exploit could grant the attacker elevated privileges on the computer.







 

Privacy Statement
Copyright 2009, SecurityFocus