A vulnerability in PHP allows bypassing restrictions set in php.ini.

A method to bypass restrictions in the PHP interpreter set by the disable_functions directive and other settings in php.ini has been published. Remember, the disable_functions directive allows the prohibition of specific internal functions in scripts; for example, you can restrict "system, exec, passthru, popen, proc_open, and shell_exec" to block the execution of external programs, or fopen to prevent file openings.

Notably, the proposed exploit utilizes a vulnerability that was reported to PHP developers more than 10 years ago, but they deemed it an insignificant issue that does not affect security. The suggested attack method is based on altering parameter values in the process memory and works in all current versions of PHP starting from PHP 7.0 (the attack is also possible in PHP 5.x, but that requires changes to the exploit). The exploit has been tested on various configurations of Debian, Ubuntu, CentOS, and FreeBSD with PHP in cli, fpm, and apache2 module forms.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster