Bug #18553 Updated: phpinfo() allows cross-site scripting

From: Date: Thu, 25 Jul 2002 08:32:29 +0000
Subject: Bug #18553 Updated: phpinfo() allows cross-site scripting
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-15135@lists.php.net to get a copy of this message
ID: 18553 Updated by: sniper@php.net Reported By: olegpro@operamail.com -Status: Open +Status: Bogus Bug Type: Feature/Change Request Operating System: Win'2k PHP Version: 4.2.2 New Comment: Sorry, but the bug system is not the appropriate forum for asking support questions. Your problem does not imply a bug in PHP itself. For a list of more appropriate places to ask for help using PHP, please visit http://www.php.net/support.php Thank you for your interest in PHP. Previous Comments: ------------------------------------------------------------------------ [2002-07-24 20:52:16] olegpro@operamail.com Hi! phpinfo() is vulnerable to cross-site scripting. printing of _SERVER["argv"] of is vulnerable. // phpinfo.php <? phpinfo(); ?> http://localhost/phpinfo.php?z=<SCRIPT>alert('Hello world!');</SCRIPT> ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=18553&edit=1

« previous php.bugs (#15135) next »