Bug #18553 Updated: phpinfo() allows cross-site scripting
| From: | sniper@php.net | Date: | Thu, 25 Jul 2002 08:32:29 +0000 |
| Subject: | Bug #18553 Updated: phpinfo() allows cross-site scripting | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-15135@lists.php.net to get a copy of this message | ||
ID: 18553
Updated by: sniper@php.net
Reported By: olegpro@operamail.com
-Status: Open
+Status: Bogus
Bug Type: Feature/Change Request
Operating System: Win'2k
PHP Version: 4.2.2
New Comment:
Sorry, but the bug system is not the appropriate forum for asking
support questions. Your problem does not imply a bug in PHP itself.
For a list of more appropriate places to ask for help using PHP,
please visit http://www.php.net/support.php
Thank you for your interest in PHP.
Previous Comments:
------------------------------------------------------------------------
[2002-07-24 20:52:16] olegpro@operamail.com
Hi!
phpinfo() is vulnerable to cross-site scripting.
printing of _SERVER["argv"] of is vulnerable.
// phpinfo.php
<?
phpinfo();
?>
http://localhost/phpinfo.php?z=<SCRIPT>alert('Hello
world!');</SCRIPT>
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=18553&edit=1