Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHP posix_getpwnam / posix_getpwuid safe_mode Circumvention Vulnerability

PHP is a server side scripting language, designed to be embedded within HTML files. It is available for Windows, Linux, and many Unix based operating systems. It is commonly used for web development, and is very widely deployed.

PHP safe_mode and open_basedir do not restrict the usage of posix_getpwnam and posix_getpwuid, allowing malicious scripts to access information related to local users of the system. Brute force enumeration of all user accounts is possible.







 

Privacy Statement
Copyright 2009, SecurityFocus