vendor:
PHP
by:
Stefan Esser
7.5
CVSS
HIGH
Remote File Inclusion
CWE
Product Name: PHP
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
PHP _SESSION unset() Vulnerability
This code demonstrates a vulnerability in the PHP _SESSION unset() function that can be exploited for remote file inclusion. The code includes a shellcode that is executed when the vulnerability is triggered.
Mitigation:
Remove or fix the vulnerability in the PHP _SESSION unset() function. Update to a patched version of PHP.