>> PHP "sscanf()" Format Specifier Handling Security Bypass and Code Execution Vulnerability
Title : PHP "sscanf()" Format Specifier Handling Security Bypass and Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2006-3193 CVE ID : CVE-2006-4020
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-08-08
Technical Description
A vulnerability has been identified in PHP, which could be exploited by local attackers to bypass security restrictions. This flaw is due to an error in the "sscanf()" PHP function when processing format specifiers, which could be exploited by malicious users to bypass safe mode and execute arbitrary code.