Bug #78573 [Nab]: XSS via file name

From: Date: Fri, 20 Sep 2019 08:19:33 +0000
Subject: Bug #78573 [Nab]: XSS via file name
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222843@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78573&edit=1

 ID:                 78573
 Updated by:         kalle@php.net
 Reported by:        manamtabeshekan at gmail dot com
 Summary:            XSS via file name
 Status:             Not a bug
 Type:               Bug
 Package:            Output Control
 PHP Version:        7.3.9
 Block user comment: N
 Private report:     N

 New Comment:

If you are not interested in the error, then please consult the error supression operator:
https://www.php.net/manual/en/language.operators.errorcontrol.php


Previous Comments:
------------------------------------------------------------------------
[2019-09-20 08:02:45] requinix@php.net

Please don't shoot yourself in the foot.

------------------------------------------------------------------------
[2019-09-20 07:58:49] manamtabeshekan at gmail dot com

Description:
------------
Displaying error messages (filename) is vulnerable to XSS, We just need to set the name of a PHP
file to something like this: <img src=x
onerror=alert('XSS')>.php

Test script:
---------------
<img src=x onerror=alert('XSS')>.php:

<?php

$file = $_GET['f'];
$f = fopen($file, 'r');

?>


Expected result:
----------------
When you open this file in your browser you will get 2 XSS popups.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=78573&edit=1


Thread (3 messages)

« previous php.bugs (#222843) next »