ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by reading arbitrary files via the ioncube_read_file function.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2007-10-14 11:17
Updated : 2017-09-28 18:29
NVD link : CVE-2007-5447
Mitre link : CVE-2007-5447
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
ioncube
- php_encoder
php
- php