vendor:
PHP
by:
Abysssec Inc
5.5
CVSS
MEDIUM
SafeMod Bypass
CWE
Product Name: PHP
Affected Version From: 5.2.2000
Affected Version To: 5.2.2009
Patch Exists: NO
Related CWE:
CPE: a:php:php:5.2.9
Platforms Tested: Windows
2009
PHP <= 5.2.9 SafeMod Bypass Vulnerability
There is a SafeMod bypass vulnerability in PHP <= 5.2.9 on Windows. The issue arises from the implementation and interfacing between PHP and the operating system's directory structure. PHP does not differentiate between directory browsing in Linux and Windows, allowing an attacker to execute commands on the target machine even with SafeMod enabled (php.ini setting).
Mitigation:
Upgrade PHP to a version higher than 5.2.9. Consider implementing additional security measures such as using a web application firewall.