[thelist] FYI (php-apache security hole)

Scott Dexter sgd at ti3.com
Mon Jan 28 17:31:04 CST 2002


* SCRIPT EXECUTION VULNERABILITY IN PHP 4.0 FOR APACHE
Paul Brereton discovered a vulnerability in PHP 4.0 for Windows using
Apache Web
Server 2.0. By exploiting PHP's ability to view files residing outside
the usual
HTML root directory, an attacker can execute arbitrary code by inserting
a
malicious PHP-based command into the Apache log file. PHP has been
notified, but
no fix is currently available.
   http://www.secadministrator.com/articles/index.cfm?articleid=23887

sgd
--
work: http://ti3.com/
non: http://thinksafely.org/



More information about the thelist mailing list