Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2004-0542
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-0542

Description:
PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arbitrary code, overwrite files, and access internal environment variables via (1) the "%", "|", or ">" characters to the escapeshellcmd function, or (2) the "%" character to the escapeshellarg function.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/16331

MISC
  http://www.idefense.com/application/poi/display?id=108

CONFIRM
  http://www.php.net/release_4_3_7.php


Return to the previous page.