Record summary

CVE-2004-2692 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.

Description

The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass restrictions and execute arbitrary commands via a backtick operator, which is not handled using the php_escape_shell_cmd function.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBPHP 4.3.7 - 'php-exec-dir' Patch Command Access Restriction BypassExploitDB exploitby VeNoMouSNot analyzed1 file
ExploitDB

PoC details

References

9