|
» Topic: Critical php_admin* bypass by ini_restore()
» Added by: Maksymilian Arciemowicz
» Date: 9.9.2006
SecurityReason realised new advisory about vulnerabilities in PHP 5/4 "PHP 5.1.6 / 4.4.4 Critical php_admin* bypass by ini_restore()". The main problem exist in the ini_restore() function. We could bypass local values from php config.
More info:
http://securityreason.com/achievement_securityalert/42
|