Bug #76042 [Com]: XMLReader::read() Information Leaked

From: Date: Fri, 02 Mar 2018 23:02:05 +0000
Subject: Bug #76042 [Com]: XMLReader::read() Information Leaked
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214188@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76042&edit=1 ID: 76042 Comment by: spam2 at rhsoft dot net Reported by: zhihua dot yao at dbappsecurity dot com dot cn Summary: XMLReader::read() Information Leaked Status: Not a bug Type: Bug Package: XML Reader PHP Version: 7.2.3 Block user comment: N Private report: N New Comment: when your webserver is allowed to read /etc unconditional you are lost anyways - full stop Previous Comments: ------------------------------------------------------------------------ [2018-03-02 22:00:33] stas@php.net This understanding is incorrect, error messages can contain other things and it is explicitly insecure to leave error messages exposed to site visitors. Not only this is not a security issue, this is not an issue at all, it's working as it was supposed to. ------------------------------------------------------------------------ [2018-03-02 08:26:21] zhihua dot yao at dbappsecurity dot com dot cn According to my understanding, because this is not an xml, it should not output anything that is not xml. ------------------------------------------------------------------------ [2018-03-02 08:17:19] stas@php.net Sorry, but your problem does not imply a bug in PHP itself. For a list of more appropriate places to ask for help using PHP, please visit http://www.php.net/support.php as this bug system is not the appropriate forum for asking support questions. Due to the volume of reports we can not explain in detail here why your report is not a bug. The support channels will be able to provide an explanation for you. Thank you for your interest in PHP. ------------------------------------------------------------------------ [2018-03-02 08:17:05] stas@php.net Of course it read the file, you told it to read the file. ------------------------------------------------------------------------ [2018-03-02 07:22:38] zhihua dot yao at dbappsecurity dot com dot cn Warning: XMLReader::read(): root:x:0:0:root:/root:/bin/bash in /home/hackyzh/Desktop/poc.php on line 5 It read the file '/etc/passwd'. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76042 -- Edit this bug report at https://bugs.php.net/bug.php?id=76042&edit=1

« previous php.bugs (#214188) next »