ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by reading arbitrary files via the ioncube_read_file function.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/4517 | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/37227 | vdb entry |
http://osvdb.org/41708 | vdb entry |
http://www.securityfocus.com/bid/26024 | vdb entry |
http://secunia.com/advisories/27178 | third party advisory vendor advisory |