Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PHP 5 before 5.2.7 does not enforce the error_log safe_mode restrictions when safe_mode is enabled through a php_admin_flag setting in httpd.conf, which allows context-dependent attackers to write to arbitrary files by placing a "php_value error_log" entry in a .htaccess file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP error_log绕过安全模式限制漏洞
Vulnerability Description
PHP是广泛使用的通用目的脚本语言,特别适合于Web开发,可嵌入到HTML中。 PHP 5 5.2.7以前版本httpd.conf php_admin_flag 设置中的safe_mode被激活的情况下,php无法执行error_log 安全策略,这个允许远程攻击者在.htaccess 文件中放置一个php_value error_log的入口来写入任意的文件。
CVSS Information
N/A
Vulnerability Type
N/A