ID: 14883 Updated by: [EMAIL PROTECTED] Reported By: [EMAIL PROTECTED] Status: Open Bug Type: Apache related Operating System: Windows NT (all Win32) PHP Version: 4.1.1 New Comment:
Actually, this exploit allows anyone to gain root access to the Machine and so the severity should be ugraded to High. Previous Comments: ------------------------------------------------------------------------ [2002-01-06 02:12:42] [EMAIL PROTECTED] Report yesterday (4 Jan 02) at http://www.securiteam.com/windowsntfocus/5ZP030U60U.html outlines the security hole. I have tested it on NT4, Apache 1.3.9, PHP 4.0.4 and then upgraded to NT4, Apache 1.3.22, PHP 4.1.1 and the problem remains. I've been monitoring the PHP newsgroups (announcements and Windows user lists) since the vulnerability was announced and searched the buglist but haven't found mention of it anywhere. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=14883&edit=1