The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass restrictions and execute arbitrary commands via a backtick operator, which is not handled using the php_escape_shell_cmd function.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2004-12-30 21:00
Updated : 2017-07-28 18:29
NVD link : CVE-2004-2692
Mitre link : CVE-2004-2692
JSON object : View
Products Affected
kyberdigi_labs
- php-exec-dir