Bug #13406 Updated: PHP exploit

From: Date: Sun, 23 Sep 2001 18:35:48 +0000
Subject: Bug #13406 Updated: PHP exploit
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-66408@lists.php.net to get a copy of this message
ID: 13406 Updated by: jeroen Reported By: arpadffy@altavista.net Old Status: Open Status: Bogus Bug Type: *General Issues Operating System: Linux PHP Version: 4.0.4pl1 New Comment: Ask support questions on http://www.php.net/support.php Hint: safe-mode, safemode.disable-function (or something like that) Previous Comments: ------------------------------------------------------------------------ [2001-09-23 14:27:10] arpadffy@altavista.net I'm running Redhat 7.1 Linux xxxxxxxxxxxx 2.4.3-12 #1 Fri Jun 8 15:05:56 EDT 2001 i686 unknown with apache apache-1.3.19-5 funcion system() gives apache rights to every user even in /~username requests... it is easy to exploit the whole site with simple script http://www.gimpster.com/php/phpshell/index.php what should I do againt.?? ------------------------------------------------------------------------ Edit this bug report at http://bugs.php.net/?id=13406&edit=1

« previous php.dev (#66408) next »