Bug #78573 [Nab]: XSS via file name
Edit report at https://bugs.php.net/bug.php?id=78573&edit=1
ID: 78573
Updated by: kalle@php.net
Reported by: manamtabeshekan at gmail dot com
Summary: XSS via file name
Status: Not a bug
Type: Bug
Package: Output Control
PHP Version: 7.3.9
Block user comment: N
Private report: N
New Comment:
If you are not interested in the error, then please consult the error supression operator:
https://www.php.net/manual/en/language.operators.errorcontrol.php
Previous Comments:
------------------------------------------------------------------------
[2019-09-20 08:02:45] requinix@php.net
Please don't shoot yourself in the foot.
------------------------------------------------------------------------
[2019-09-20 07:58:49] manamtabeshekan at gmail dot com
Description:
------------
Displaying error messages (filename) is vulnerable to XSS, We just need to set the name of a PHP
file to something like this: <img src=x
onerror=alert('XSS')>.php
Test script:
---------------
<img src=x onerror=alert('XSS')>.php:
<?php
$file = $_GET['f'];
$f = fopen($file, 'r');
?>
Expected result:
----------------
When you open this file in your browser you will get 2 XSS popups.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78573&edit=1
Thread (3 messages)