Sec Bug->Bug #71559 [Opn]: Built-in HTTP server, we can downlaod file in web by bug

From: Date: Tue, 09 Feb 2016 20:05:16 +0000
Subject: Sec Bug->Bug #71559 [Opn]: Built-in HTTP server, we can downlaod file in web by bug
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199139@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71559&edit=1 ID: 71559 Updated by: stas@php.net Reported by: setbanned at gmail dot com Summary: Built-in HTTP server, we can downlaod file in web by bug Status: Open -Type: Security +Type: Bug -Package: PHP options/info functions +Package: Built-in web server Operating System: Windows only PHP Version: 7.0.3 Block user comment: N Private report: Y New Comment: Not a security issue since built-in server should not be used in production, but somebody may want to look at it and fix it still. Previous Comments: ------------------------------------------------------------------------ [2016-02-09 12:49:40] setbanned at gmail dot com Description: ------------ Built-pool HTTP Downlaod Exploit. Exploit By : TaWaN (2600 Thailand , KissShot - Studio , Tawan Naultang , Phitchayaphong Tantikul) Software : PHP Built-in HTTP server Version : 5.4.x , 5.6.x , 7.0.x Os : Windows only How to Exploit put . (dot) attach type in url example : http://locahost:8000/index.php. we can download file in Web and look code in file. Test script: --------------- image1 : http://www.mx7.com/i/680/lsaMUF.png image2 : http://www.mx7.com/i/a49/RzFIyT.png image3 : http://www.mx7.com/i/54b/2BjHvz.png image4 : http://www.mx7.com/i/ee5/O2YHsc.png Actual result: -------------- we can downlaod file of the web. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71559&edit=1

« previous php.bugs (#199139) next »