Vulnerabilities > CVE-2000-0059 - Unspecified vulnerability in PHP

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
php
critical
exploit available

Summary

PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.

Exploit-Db

descriptionPHP 3.0.13 'safe_mode' Failure Vulnerability. CVE-2000-0059. Remote exploit for php platform
idEDB-ID:19708
last seen2016-02-02
modified2000-01-04
published2000-01-04
reporterKristian Koehntopp
sourcehttps://www.exploit-db.com/download/19708/
titlePHP <= 3.0.13 - 'safe_mode' Failure Vulnerability