PT-2011-1233 · Php+4 · Php+4

Publicado

2011-01-18

·

Atualizado

2024-06-15

·

CVE-2006-7243

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.3.4
Description The issue allows context-dependent attackers to bypass intended access restrictions. This can be achieved by placing a safe file extension after the 0 character in a pathname. For example, using .php0.jpg at the end of the argument to the file exists function. The vulnerability exists due to insufficient input validation in the file exists function of the PHP interpreter, which can be exploited by a remote attacker to bypass existing security restrictions.
Recommendations For PHP versions prior to 5.3.4, update to version 5.3.4 or later to resolve the issue. As a temporary workaround, consider validating and sanitizing all input to the file exists function to prevent the use of the 0 character in pathnames.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-02597
CESA-2013_1615
CVE-2006-7243
HPSBUX02741
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
OPENSUSE-SU-2024:11169-1
RHSA-2013:1307
RHSA-2013:1615
RHSA-2013_1307
RHSA-2013_1615
RHSA-2014:0311
RHSA-2014_0311
SUSE-SU-2016:1638-1

Produtos afetados

Centos
Hp-Ux
Php
Red Hat
Suse