Bug #68726 [Opn->Nab]: Full Path Disclosure Vulnerability

From: Date: Fri, 02 Jan 2015 14:05:57 +0000
Subject: Bug #68726 [Opn->Nab]: Full Path Disclosure Vulnerability
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189600@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68726&edit=1 ID: 68726 Updated by: leigh@php.net Reported by: muratyilmazlar1 at gmail dot com Summary: Full Path Disclosure Vulnerability -Status: Open +Status: Not a bug Type: Bug -Package: MySQL related +Package: *Configuration Issues Operating System: Windows, Linux PHP Version: Irrelevant Block user comment: N Private report: N New Comment: Thank you for taking the time to write to us, but this is not a bug. Please double-check the documentation available at http://www.php.net/manual/ and the instructions on how to report a bug at http://bugs.php.net/how-to-report.php This is a configuration issue. You need to turn off the display_errors option. Previous Comments: ------------------------------------------------------------------------ [2015-01-02 13:14:01] muratyilmazlar1 at gmail dot com Description: ------------ Although in itself does not lead to a real risk of attack, it allows you to go back to the internal structure of a server via a website and then to have more information to be used in case of pentesting, putting at risk not only the safety of the site but around the server that supplies. Test script: --------------- Here is the official website: http://faq.phpmyfaq.de/cron.verifyurls.php version: 2.8.12 https://joker.com/faq/cron.verifyurls.php version: 2.7.7 Expected result: ---------------- You can reach full path of website and server. Actual result: -------------- It could help hackers to hack site and sniffing. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68726&edit=1

« previous php.bugs (#189600) next »