J
j Zim
Guest
It seems that a customer was able to upload a php file into the /tmp directory and then call a sh command (php <name of its file.php>) to execute the script.
At the moment I have no idea from what domain this is done but as a quick fix I would like to disable the possibility to execute sh/shell command for all my customers using PHP script.
Is that possible changing the php5.ini file or doing it this way I'll have some trouble with Plesk or other admin script (like phpmyadmin, etc.)?
Thanks in advance for your help.
JZ
At the moment I have no idea from what domain this is done but as a quick fix I would like to disable the possibility to execute sh/shell command for all my customers using PHP script.
Is that possible changing the php5.ini file or doing it this way I'll have some trouble with Plesk or other admin script (like phpmyadmin, etc.)?
Thanks in advance for your help.
JZ
Last edited by a moderator: