PHP 4.0 Bug #8391: as Apache module, PHP errors should not reveal absolute file paths
| From: | madizen at tds dot net | Date: | Sun, 24 Dec 2000 00:46:51 +0000 |
| Subject: | PHP 4.0 Bug #8391: as Apache module, PHP errors should not reveal absolute file paths | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-42191@lists.php.net to get a copy of this message | ||
From: madizen@tds.net
Operating system: FreeBSD 4.2-STABLE
PHP version: 4.0.3pl1
PHP Bug Type: Feature/Change Request
Bug description: as Apache module, PHP errors should not reveal absolute file paths
When PHP is installed as an Apache module (using Apache and PHP port installers from FreeBSD), and a
script contains syntax errors or encounters problems while in use (e.g. unable to open a file with
fopen), errors are reported to the browser window which reveal the absolute file path to the script
rather than the relative path known by Apache, e.g. /private/database/area/php/script.php instead of
/php/script.php, assuming the Apache root document directory is /private/database/area/. In several
other instances, similar problems with web products (IIS, et. al.) revealing the absolute paths to
their virtual environments have been labeled "bugs" or "security leaks". Please
consider whether the absolute path can/should be masked whenever discretion can be obtained. I
apologize if this is a configurable behavior and I just can't find the toggle, but perhaps
discretion should be the default behavior if such a toggle exists. Thank you for your consideration.
--
Edit Bug report at: http://bugs.php.net/?id=8391&edit=1