[<prev] [next>] [day] [month] [year] [list]
Message-ID: <586259.73521.qm@web90405.mail.mud.yahoo.com>
Date: Tue, 25 Dec 2007 05:20:06 -0800 (PST)
From: Alireza Hassani <trueend5@...oo.com>
To: bugtraq@...urityfocus.com
Subject: Re: Re: PHP <= 5.2.5 Safe Mode Bypass
--- shsuff@...mail.com wrote:
> Nothing new.
> Already found: http://securityreason.com/achievement_securityalert/36/
I think itÂ’s obvious that this one focuses on safe_mode restriction weakness and that one talks
about open_basedir! The only Similarity between these two advisories is the vulnerable tempnam
function
>
> And this will not bypass safe_mode but open_basedir ...
>
Which one do you talk about , this or that?
____________________________________________________________________________________
Looking for last minute shopping deals?
Find them fast with Yahoo! Search. http://tools.search.yahoo.com/newsearch/category.php?category=shopping
Powered by blists - more mailing lists