Re: Fwd: CHINANSL Security Advisory(CSA-200011)
| From: | Ron Chmara | Date: | Sun, 10 Dec 2000 18:43:52 +0000 |
| Subject: | Re: Fwd: CHINANSL Security Advisory(CSA-200011) | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-40754@lists.php.net to get a copy of this message | ||
Tried 3.0.12 on RH Linux 6.2... no effect, wandered up
and down the tree (added, and removed ../..\). I think it may
require an OS that uses "\" for paths (%5c).
Zeev Suraski wrote:
>
> Has anybody taken a look at it?
>
> >APACHE WEB SERVER 1.3
> >¡¡¡¡- Microsoft Windows NT 4.0
> >¡¡¡¡- Microsoft Windows 2000
> >Impact:
> >======
> >
> >CHINANSL security team has found a security
> >problem in Apache web server
> >where using php3. Exploitation of this vulnerability, A
> >malicious user
> >can access the content of file in the machine where
> >Apache web server
> >is runing.
> >http://taget/index.php3.%5c../..%5cconf/httpd.conf
> >You will get the httpd.conf file.
--
Personal: ron@opus1.com, 520-326-6109, http://www.opus1.com/ron/
Work: rchmara@pnsinc.com, 520-546-8993, http://www.pnsinc.com/
The opinions expressed in this email are not neccesarrily those of myself,
my employers, or any of the other little voices in my head.