News Feed
Jobs Feed
Sections

Recent Jobs

News Archive
Secunia.com:
PHP "glob()" Code Execution Vulnerability
July 16, 2007 @ 13:52:38

As reported here on Secunia (as discovered by shinnai), there's a code execution vulnerability in PHP's glob function:

The vulnerability is caused due to an error in the handling of an uninitialized structure inside the "glob()" function. This can be exploited to execute arbitrary code, which may lead to security restrictions (e.g. the "disable_functions" directive) being bypassed.

The vulnerability is confirmed in the 5.2.3 win32 installer. Other versions may also be affected.

The issue is marked as "less critical" and can be avoided easily by only allowing trusted users the correct permissions to execute PHP code on the server.

0 comments voice your opinion now!
glob vulnerability execution code bypass security glob vulnerability execution code bypass security



Similar Posts

Evolt.org: Quick Calendar Using AJAX and PHP

Zend Developer Zone: Upcoming Zend Webinars

Secunia.com: Ubuntu update for PHP

Secunis.com: Travelsized CMS index.php Cross-Site Scripting Vulnerabilities

ThinPHP Blog: Understanding successful tracing of security vulnerabilities


Community Events







Don't see your event here?
Let us know!


book application package job PEAR database releases developer ajax zendframework cakephp PHP5 mysql framework example code zend security conference release

All content copyright, 2008 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework