PHP 'session.save_path()' Arbitrary Code Execution Vulnerability

Attackers can exploit this issue to run arbitrary code within the context of the PHP process. This may allow them to bypass intended security restrictions or gain elevated privileges.

Versions prior to PHP 5.2.12 are vulnerable.


 

Privacy Statement
Copyright 2010, SecurityFocus