New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Added support for php5 as target #10487
Conversation
location of the session file in php5 is /var/lib/php5/sess_file
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hmm, I would go about this differently. I would leave Linux as the Linux target and not differentiate php versions. Then change data path to be an array and loop through that way it can check php5, php6, php7, php8 and php.
That makes it more future proof and automates the task of fidning the file so the user doesn't have to
I agree with @h00die, I think this is too minor of a variation to have a separate target. |
Agree with @h00die and @acammack-r7. |
I opened a PR on @CJHackerz repo to use an array for the file paths. |
Additional path for Linux target
Release NotesAn additional session file path has been added in the exploits/multi/http/phpmyadmin_lfi_rce module for the Linux target. The additional path adds support for php5 session files. |
location of the session file in php5 is /var/lib/php5/sess_file