>> PHP "curl_init()" Function Null Byte Character Safe Mode Bypass Vulnerability
Title : PHP "curl_init()" Function Null Byte Character Safe Mode Bypass Vulnerability VUPEN ID : VUPEN/ADV-2006-2055 CVE ID : GENERIC-MAP-NOMATCH
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-05-30
Technical Description
A vulnerability has been identified in PHP, which could be exploited by malicious users to bypass security restrictions. This flaw is due to an error in the cURL extension that does not properly handle null byte characters passed to the "curl_init()" function, which could be exploited by local attackers to bypass safe mode restrictions and gain unauthorizd access to arbitrary scripts.