I was just giving my PHP a bit of a spin, and I noticed that opendir
opens EVERYTHING, and unix commands can be executed with the ' grave,
like this 'ls -lR /'.
Can someone quantify how slack this is? Is it normal practice amongst
large servers?
When the security is this crap, what else can happen?
opens EVERYTHING, and unix commands can be executed with the ' grave,
like this 'ls -lR /'.
Can someone quantify how slack this is? Is it normal practice amongst
large servers?
When the security is this crap, what else can happen?
Comment