Bug #78573 [NEW]: XSS via file name

From: Date: Fri, 20 Sep 2019 07:58:49 +0000
Subject: Bug #78573 [NEW]: XSS via file name
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222841@lists.php.net to get a copy of this message
From: manamtabeshekan at gmail dot com Operating system: PHP version: 7.3.9 Package: Output Control Bug Type: Bug Bug description:XSS via file name Description: ------------ Displaying error messages (filename) is vulnerable to XSS, We just need to set the name of a PHP file to something like this: <img src=x onerror=alert('XSS')>.php Test script: --------------- <img src=x onerror=alert('XSS')>.php: <?php $file = $_GET['f']; $f = fopen($file, 'r'); ?> Expected result: ---------------- When you open this file in your browser you will get 2 XSS popups. -- Edit bug report at https://bugs.php.net/bug.php?id=78573&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=78573&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=78573&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=78573&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=78573&r=needscript Try newer version: https://bugs.php.net/fix.php?id=78573&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=78573&r=support Expected behavior: https://bugs.php.net/fix.php?id=78573&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=78573&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=78573&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=78573&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=78573&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=78573&r=dst IIS Stability: https://bugs.php.net/fix.php?id=78573&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=78573&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=78573&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=78573&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=78573&r=mysqlcfg

« previous php.bugs (#222841) next »