Sec Bug->Bug #76042 [Nab]: XMLReader::read() Information Leaked

From: Date: Fri, 02 Mar 2018 22:00:35 +0000
Subject: Sec Bug->Bug #76042 [Nab]: XMLReader::read() Information Leaked
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214187@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76042&edit=1 ID: 76042 Updated by: stas@php.net Reported by: zhihua dot yao at dbappsecurity dot com dot cn Summary: XMLReader::read() Information Leaked Status: Not a bug -Type: Security +Type: Bug Package: XML Reader PHP Version: 7.2.3 Block user comment: N Private report: Y New Comment: This understanding is incorrect, error messages can contain other things and it is explicitly insecure to leave error messages exposed to site visitors. Not only this is not a security issue, this is not an issue at all, it's working as it was supposed to. Previous Comments: ------------------------------------------------------------------------ [2018-03-02 08:26:21] zhihua dot yao at dbappsecurity dot com dot cn According to my understanding, because this is not an xml, it should not output anything that is not xml. ------------------------------------------------------------------------ [2018-03-02 08:17:19] stas@php.net Sorry, but your problem does not imply a bug in PHP itself. For a list of more appropriate places to ask for help using PHP, please visit http://www.php.net/support.php as this bug system is not the appropriate forum for asking support questions. Due to the volume of reports we can not explain in detail here why your report is not a bug. The support channels will be able to provide an explanation for you. Thank you for your interest in PHP. ------------------------------------------------------------------------ [2018-03-02 08:17:05] stas@php.net Of course it read the file, you told it to read the file. ------------------------------------------------------------------------ [2018-03-02 07:22:38] zhihua dot yao at dbappsecurity dot com dot cn Warning: XMLReader::read(): root:x:0:0:root:/root:/bin/bash in /home/hackyzh/Desktop/poc.php on line 5 It read the file '/etc/passwd'. ------------------------------------------------------------------------ [2018-03-02 06:54:19] stas@php.net Where is the security issue? You read the file, it's not XML, you get some warnings. Where's the security issue? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76042 -- Edit this bug report at https://bugs.php.net/bug.php?id=76042&edit=1

« previous php.bugs (#214187) next »