Vulnerabilities > CVE-2004-2692 - Configuration vulnerability in Kyberdigi Labs PHP-Exec-Dir

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
kyberdigi-labs
CWE-16
exploit available

Summary

The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass restrictions and execute arbitrary commands via a backtick operator, which is not handled using the php_escape_shell_cmd function.

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionPHP (php-exec-dir) Patch Command Access Restriction Bypass. CVE-2004-2692. Webapps exploit for php platform
idEDB-ID:384
last seen2016-01-31
modified2004-08-08
published2004-08-08
reporterVeNoMouS
sourcehttps://www.exploit-db.com/download/384/
titlePHP php-exec-dir Patch Command Access Restriction Bypass