Description
The disable_functions feature in PHP 4 and 5 allows attackers to bypass intended restrictions by using an alias, as demonstrated by using ini_alter when ini_set is disabled.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/482006/100/0/threaded
Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/3216
Various Sources x_refsource_misc
http://securityvulns.com/news/PHP/alias-pb.html
Various Sources x_refsource_misc
http://securityvulns.ru/Sdocument67.html
Scores
EPSS
0.0032
EPSS Percentile
55.4%
Details
Status
published
Products (2)
php/php
4.0
php/php
5.0.0
Published
Oct 12, 2007
Tracked Since
Feb 18, 2026