Secunia
|
|

CVE Reference: CVE-2004-1063 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2004-1063 |
|
|
Description: PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multithreaded Unix webserver, allows local users to bypass safe_mode_exec_dir restrictions and execute commands outside of the intended safe_mode_exec_dir via shell metacharacters in the current directory name. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion. |
|
|
CVE Status: Candidate |
|
|
References: XF http://xforce.iss.net/xforce/xfdb/18511 UBUNTU http://marc.theaimsgroup.com/?l=bugtraq&m=111117104809638&w=2 OSVDB 12412 MISC http://www.hardened-php.net/advisories/012004.txt MANDRAKE http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:072 http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:151 HP http://www.securityfocus.com/advisories/9028 GENTOO http://www.gentoo.org/security/en/glsa/glsa-200412-14.xml CONFIRM http://www.php.net/release_4_3_10.php CONECTIVA http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000915 BUGTRAQ http://www.securityfocus.com/archive/1/384545 BID 11964 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |