ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by reading arbitrary files via the ioncube_read_file function.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2007-10-14 18:17
Updated : 2025-04-09 00:30
NVD link : CVE-2007-5447
Mitre link : CVE-2007-5447
CVE.ORG link : CVE-2007-5447
JSON object : View
Products Affected
                php
- php
ioncube
- php_encoder
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
