|
» Topic: error_log() Safe Mode Bypass PHP 5.1.4 and 4.4.2
» Added by: Maksymilian Arciemowicz
» Date: 26.6.2006
SecurityReason public another advisory showing issue in PHP - "error_log() Safe Mode Bypass PHP 5.1.4 and 4.4.2". error_log is function that's send an error message somewhere (file, mail etc). Using error_log() we can easy bypass safemode. The issue isn't fixed by PHP Team, Why ? , we don't know , we were waiting with public this issue but we get no answer from PHP Team . The issue is dangerous because the function is common used in php and there is no fix.
More:
http://securityreason.com/achievement_securityalert/41
|