Bug #13406: PHP exploit
| From: | arpadffy at altavista dot net | Date: | Sun, 23 Sep 2001 18:27:10 +0000 |
| Subject: | Bug #13406: PHP exploit | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-66407@lists.php.net to get a copy of this message | ||
From: arpadffy@altavista.net
Operating system: Linux
PHP version: 4.0.4pl1
PHP Bug Type: *General Issues
Bug description: PHP exploit
I'm running Redhat 7.1
Linux xxxxxxxxxxxx 2.4.3-12 #1 Fri Jun 8 15:05:56 EDT 2001 i686 unknown
with apache apache-1.3.19-5
funcion system() gives apache rights to every user even in /~username
requests...
it is easy to exploit the whole site with simple script
http://www.gimpster.com/php/phpshell/index.php
what should I do againt.??
--
Edit bug report at: http://bugs.php.net/?id=13406&edit=1