PHP 4.0 Bug #6366: Security vulnerability for bad url file names with IIS PHP
| From: | joel at intwebservices dot com | Date: | Sat, 26 Aug 2000 13:11:51 +0000 |
| Subject: | PHP 4.0 Bug #6366: Security vulnerability for bad url file names with IIS PHP | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-30731@lists.php.net to get a copy of this message | ||
From: joel@intwebservices.com
Operating system: Windows NT 4.0
PHP version: 4.0.1pl2
PHP Bug Type: Other
Bug description: Security vulnerability for bad url file names with IIS PHP
If you put a bad file name in the url the error message shows the hard drive directory structure.
No script necessary.
Just put any bad file name in a url for an IIS web server
cgi version:
Fatal error: Unable to open S:\awebsites\websiteman\html\*a.php in Unknown on line 0
isapi version
Warning: Failed opening 'S:\awebsites\websiteman\html\*a.phpi' for inclusion
(include_path='') in Unknown on line 0