CVE-2007-5447 – PHP 5.2.4 ionCube - 'ioncube_read_file' Safe Mode / disable_functions Bypass
https://notcve.org/view.php?id=CVE-2007-5447
ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by reading arbitrary files via the ioncube_read_file function. ioncube_loader_win_5.2.dll en la extensión ionCube Loader 6.5 para PHP 5.2.4 no sigue las restricciones safe_mode y disable_functions, lo cual permite a atacantes locales o remotos (dependiendo del contexto) evitar las limitaciones pretendidas, como se ha demostrado leyendo archivos de su elección mediante la función ioncube_read_file. • https://www.exploit-db.com/exploits/4517 http://osvdb.org/41708 http://secunia.com/advisories/27178 http://www.securityfocus.com/bid/26024 https://exchange.xforce.ibmcloud.com/vulnerabilities/37227 • CWE-264: Permissions, Privileges, and Access Controls •