vendor:
PHP
by:
shinnai
5.5
CVSS
MEDIUM
Bypass protection
CWE
Product Name: PHP
Affected Version From: PHP 5.2.4
Affected Version To: PHP 5.2.4
Patch Exists: NO
Related CWE:
CPE: a:php:php:5.2.4
Platforms Tested: Windows XP Pro SP2
2007
PHP 5.2.4 ionCube extension safe_mode and disable_functions protections bypass
This exploit allows an attacker to bypass the safe_mode and disable_functions protections of the ionCube extension in PHP 5.2.4. By changing the file path, an attacker can retrieve sensitive information, such as source code and password files. The exploit works on Windows XP Pro SP2 with full patches and can be executed from the command line or Apache server.
Mitigation:
Upgrade to a newer version of PHP that includes a fix for this vulnerability. Alternatively, remove or disable the ionCube extension.