Monday, April 2, 2007

PHP Hash Table Overwrite Arbitrary Code Execution Vulnerability

The session extension does not set the correct reference count value for the session variables, because it does not include the internal pointer from within the session globals. Due to this unsetting _SESSION and HTTP_SESSION_VARS will destroy the Hashtable containing the session data although the session extension still has an internal pointer toUpgrade you PHP people...



read more | digg story

1 comment:

Anonymous said...

Keep up the good work.