Description
PHP 5.2.0 and 4.4 allows local users to bypass safe_mode and open_basedir restrictions via a malicious path and a null byte before a ";" in a session_save_path argument, followed by an allowed path, which causes a parsing inconsistency in which PHP validates the allowed path but sets session.save_path to the malicious path.
Remediation
References
Related Vulnerabilities
Liferay DXP Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-26271)
Next.js Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2024-46982)
WordPress Plugin Simple File List Arbitrary File Download (3.2.7)
WordPress Plugin iThemes Security (formerly Better WP Security) Unspecified Vulnerability (6.9.0)