suPHP 'suPHP_ConfigPath' Safe Mode Restriction-Bypass Vulnerability
BID:33073
Info
suPHP 'suPHP_ConfigPath' Safe Mode Restriction-Bypass Vulnerability
| Bugtraq ID: | 33073 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 31 2008 12:00AM |
| Updated: | Jan 02 2009 08:02PM |
| Credit: | Mr.SaFa7 |
| Vulnerable: |
suPHP suPHP 0.7 suPHP suPHP 0.6.3 suPHP suPHP 0.6.2 suPHP suPHP 0.5.2 suPHP suPHP 0.5.1 suPHP suPHP 0.5 suPHP suPHP 0.3.1 suPHP suPHP 0.3 |
| Not Vulnerable: | |
Discussion
suPHP 'suPHP_ConfigPath' Safe Mode Restriction-Bypass Vulnerability
suPHP is prone to a 'safe_mode' restriction-bypass vulnerability.
Successful exploits may allow attackers to bypass arbitrary PHP configuration options, including the 'safe_mode' setting.
This vulnerability would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code, with the 'safe_mode' restrictions assumed to isolate the users from each other.
suPHP is prone to a 'safe_mode' restriction-bypass vulnerability.
Successful exploits may allow attackers to bypass arbitrary PHP configuration options, including the 'safe_mode' setting.
This vulnerability would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code, with the 'safe_mode' restrictions assumed to isolate the users from each other.
Exploit / POC
suPHP 'suPHP_ConfigPath' Safe Mode Restriction-Bypass Vulnerability
To exploit this issue, an attacker may use readily available tools.
The following example exploit is available:
To exploit this issue, an attacker may use readily available tools.
The following example exploit is available:
Solution / Fix
suPHP 'suPHP_ConfigPath' Safe Mode Restriction-Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
suPHP 'suPHP_ConfigPath' Safe Mode Restriction-Bypass Vulnerability
References:
References: