Bugtraq mailing list archives

Re: Re: PHP <= 5.2.5 Safe Mode Bypass


From: Alireza Hassani <trueend5 () yahoo com>
Date: Tue, 25 Dec 2007 05:20:06 -0800 (PST)

--- shsuff () hotmail com wrote:

Nothing new.
Already found: http://securityreason.com/achievement_securityalert/36/

I think itÂ’s obvious that this one focuses on safe_mode restriction weakness and that one talks
about open_basedir! The only Similarity between these two advisories is the vulnerable tempnam
function


And this will not bypass safe_mode but open_basedir ...


Which one do you talk about , this or that?



      ____________________________________________________________________________________
Looking for last minute shopping deals?  
Find them fast with Yahoo! Search.  http://tools.search.yahoo.com/newsearch/category.php?category=shopping


Current thread: