Bug #17716: Webroot Disclosure in Error Output

From: Date: Tue, 11 Jun 2002 22:08:28 +0000
Subject: Bug #17716: Webroot Disclosure in Error Output
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-10167@lists.php.net to get a copy of this message
From:             mattmurphy@kc.rr.com
Operating system: Win32
PHP version:      4.2.1
PHP Bug Type:     Output Control
Bug description:  Webroot Disclosure in Error Output

PHP 4.2.1 Path Disclosure Bug

System Details:
  - Windows Me
  - PHP 4.2.1 as CGI on Xitami 2.49d
  - No modules

PHP 4.2.1 (possibly and probably others) can disclose path information in
error output.  This is due to the fact that PHP discloses the full path of
failing scripts.  For example, take the deliberately malformed
"Error.php":

<?php
@if ($action == "error") {
}
?>

This script produces the following output:

Parse error: parse error, unexpected T_IF in C:\INETPUB\WWWROOT\error.php
on line 2

As you can see, this includes the path of the web root in the error data. 
This is surplus information at best, and at worst, data that could aid an
attack against the server.

While this script produces a parse error, it should be noted that default
installs of 4.2.1 produce this on such small events as notices as well.
-- 
Edit bug report at http://bugs.php.net/?id=17716&edit=1
-- 
Fixed in CVS:        http://bugs.php.net/fix.php?id=17716&r=fixedcvs
Fixed in release:    http://bugs.php.net/fix.php?id=17716&r=alreadyfixed
Need backtrace:      http://bugs.php.net/fix.php?id=17716&r=needtrace
Try newer version:   http://bugs.php.net/fix.php?id=17716&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=17716&r=support
Expected behavior:   http://bugs.php.net/fix.php?id=17716&r=notwrong
Not enough info:     http://bugs.php.net/fix.php?id=17716&r=notenoughinfo
Submitted twice:     http://bugs.php.net/fix.php?id=17716&r=submittedtwice
register_globals:    http://bugs.php.net/fix.php?id=17716&r=globals



Thread (4 messages)

« previous php.bugs (#10167) next »