Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHP 5 'posix_access()' Function 'safe_mode' Bypass Directory Traversal Vulnerability

PHP is prone to a directory-traversal vulnerability because it fails to adequately sanitize user-supplied data.

Attackers can leverage this issue to bypass security restrictions enforced by 'safe_mode' to access data outside of the root webserver directory. Successful attacks may allow an attacker to access sensitive information that could aid in further attacks.

PHP 5.2.6 is vulnerable; other versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus