php: restriction bypass
| Package(s): | php | CVE #(s): | CVE-2006-4625 CVE-2006-5178 | ||||||||
| Created: | October 18, 2006 | Updated: | October 18, 2006 | ||||||||
| Description: | The ini_restore() function in PHP versions through 4.4.4 and 5.1.6 can be used to bypass safe_mode and init_basedir restrictions.
Also: race condition in PHP's handling of the symlink() function can enable hostile code to bypass open_basedir restrictions. | ||||||||||
| Alerts: |
| ||||||||||
