Bug #15887 Updated: vulnerability? security hole?
| From: | imajes@php.net | Date: | Tue, 12 Mar 2002 11:51:34 +0000 |
| Subject: | Bug #15887 Updated: vulnerability? security hole? | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-2290@lists.php.net to get a copy of this message | ||
ID: 15887
Updated by: imajes@php.net
Reported By: astrosmurfie@yahoo.co.uk
Status: Closed
Bug Type: Apache related
Operating System: windows 2000
PHP Version: 4.1.2
New Comment:
released.
Previous Comments:
------------------------------------------------------------------------
[2002-03-05 15:48:46] imajes@php.net
This has been fixed and will be released shortly with the new version
of php under windows.
------------------------------------------------------------------------
[2002-03-05 15:41:02] astrosmurfie@yahoo.co.uk
hi!
I just happened to see on a web page and tried that when one writes
'http://myaddress/php/php.exe?anyfile',
he can see what's in this file.
And this way, one can also upload some files and hack the system.
What do you think? Is this 'php.exe' a security hole, and what's the
use of it if I dont use it at all? I searched your web site, but
couldn't find an answer for that. Could you please give me a sufficient
explanation about the capabilities of this 'php.exe' file?
Thanks in advance!
smurfie
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=15887&edit=1