PHP undefined Safe_Mode_Include_Dir safemode bypass vulnerability
PHP undefined Safe_Mode_Include_Dir safemode bypass vulnerability
Published on 2004-03-27. Updated on 2007-03-20.
Description:
This alert was generated using only banner information. It may be a false positive.
PHP is prone to an issue that may allow programs to bypass Safe Mode by calling external files in restricted directories using include() and require().
Affected PHP versions (4.3, 4.3.1, 4.3.2).
Impact:
Unauthorized access or policy bypass in environments that use Safe Mode.
Recommendation:
Upgrade PHP to the latest version.
Alert Tags: configuration
ApplicableApplicationServer : PHP
ApplicableOS: All
ApplicableWebServer: All
References:
Go Back