PHP Python Extension 'safe_mode' Restriction Bypass Vulnerability
BID:32902
Info
PHP Python Extension 'safe_mode' Restriction Bypass Vulnerability
| Bugtraq ID: | 32902 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 17 2008 12:00AM |
| Updated: | Dec 29 2008 05:42PM |
| Credit: | Amir Salmani |
| Vulnerable: |
PHP PHP 5.2.8 PHP PHP 5.2.7 PHP PHP 5.2.6 PHP PHP 5.2.5 PHP PHP 5.2.4 PHP PHP 5.2.3 PHP PHP 5.2.2 PHP PHP 5.2.1 PHP PHP 5.2 |
| Not Vulnerable: |
PHP PHP 6.0 |
Discussion
PHP Python Extension 'safe_mode' Restriction Bypass Vulnerability
PHP is prone to a 'safe_mode' restriction-bypass vulnerability when the Python extension in enabled. Successful exploits could allow an attacker to execute arbitrary code.
This vulnerability would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code; in such cases, the 'safe_mode' restriction is expected to isolate users from each other.
Versions prior to PHP 6 are vulnerable.
NOTE: The severity of this issue can vary depending on the specific configuration of the server.
PHP is prone to a 'safe_mode' restriction-bypass vulnerability when the Python extension in enabled. Successful exploits could allow an attacker to execute arbitrary code.
This vulnerability would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code; in such cases, the 'safe_mode' restriction is expected to isolate users from each other.
Versions prior to PHP 6 are vulnerable.
NOTE: The severity of this issue can vary depending on the specific configuration of the server.
Exploit / POC
PHP Python Extension 'safe_mode' Restriction Bypass Vulnerability
Attackers may exploit these issues with standard PHP code.
The following exploit code is available:
Attackers may exploit these issues with standard PHP code.
The following exploit code is available:
Solution / Fix
PHP Python Extension 'safe_mode' Restriction Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PHP Python Extension 'safe_mode' Restriction Bypass Vulnerability
References:
References: