PHP PHP_INI_SYSTEM Ineffective Controls
Posted by deepcore on May 22, 2019 – 8:20 am
Security controls configured via php.ini directives at the PHP_INI_SYSTEM level are ineffective as they could be bypassed by malicious scripts via writing their own process memory on the Linux platform. Proof of concept code included.
Post a reply
You must be logged in to post a comment.