PHP posix_getpwnam / posix_getpwuid...

- AV AC AU C I A
发布: 2002-04-23
修订: 2025-04-13

PHP is a server side scripting language, designed to be embedded within HTML files. It is available for Windows, Linux, and many Unix based operating systems. It is commonly used for web development, and is very widely deployed. PHP safe_mode and open_basedir do not restrict the usage of posix_getpwnam and posix_getpwuid, allowing malicious scripts to access information related to local users of the system. Brute force enumeration of all user accounts is possible.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息