[PHP safe_mode bypass with exec/system/passthru] Once again php public new version :php5.2.10 ,and it fix lots of bugs, like this : Bug #45997[safe_mode bypass with exec/system/passthru] incorrect fix php5.2.10 ...        b = strrchr(cmd, PHP_DIR_SEPARATOR); #ifdef PHP_WIN32        if (b && *b == '\\' && b == cmd) {            php_error_docref(NULL TSRMLS_CC, E_WARNING, "Invalid absolute path.");            goto err;        } #endif ... exec('\dir') not be evaluated, but exec('80vul\b\dir') will. POC: reference: http://www.80vul.com/pch/pch-006.txt http://hi.baidu.com/80vul_b/blog/item/8e0ea6cea6378f34f9dc614a.html http://www.milw0rm.com/exploits/8799 http://bugs.php.net/bug.php?id=45997 -- hitest _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/