vendor:
suPHP
by:
Mr.SaFa7
7.5
CVSS
HIGH
Restriction-Bypass
264
CWE
Product Name: suPHP
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
suPHP ‘safe_mode’ Restriction-Bypass Vulnerability
suPHP is prone to a 'safe_mode' restriction-bypass vulnerability. Successful exploits may allow attackers to bypass arbitrary PHP configuration options, including the 'safe_mode' setting. This vulnerability would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code, with the 'safe_mode' restrictions assumed to isolate the users from each other.
Mitigation:
Ensure that the suPHP_ConfigPath directive is not used in .htaccess files.