Record summary

CVE-2010-1130 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the session_save_path function, which allows context-dependent attackers to bypass open_basedir and safe_mode restrictions via an argument that contains multiple ; characters in conjunction with a .. (dot dot).

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBPHP 5.3.1 - 'session_save_path() Safe_mode()' Restriction Bypass ExploiotExploitDB exploitby Grzegorz StachowiakNot analyzed1 file
ExploitDB

PoC details

References

12