CVE-2008-5625 (php) [Sitemap] - HeapOverflow Computer Security Community & Forums : Heap Overflow.com

PDA

View Full Version : CVE-2008-5625 (php)


Heap
18-12-08, 04:02
PHP 5 before 5.2.7 does not enforce the error_log safe_mode restrictions when safe_mode is enabled through a php_admin_flag setting in httpd.conf, which allows context-dependent attackers to write to arbitrary files by placing a "php_value error_log" entry in a .htaccess file.

More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5625)