PHP 4.0 Bug #10091 Updated: -
| From: | jmoore@php.net | Date: | Sat, 31 Mar 2001 15:41:33 +0000 |
| Subject: | PHP 4.0 Bug #10091 Updated: - | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-50426@lists.php.net to get a copy of this message | ||
ID: 10091
Updated by: jmoore
Reported By: megahz@the-megahz.com
Status: Bogus
Bug Type: *General Issues
Assigned To:
Comments:
Just a note to say this must have been somthing posted a long time ago (at least I didnt see it
yesterday) and is not a bug or vunrability in PHP as cynic pointed out as there are various members
of the PHP Team who watch bugtraq and react to anything related to PHP.
James
Previous Comments:
---------------------------------------------------------------------------
[2001-03-31 09:42:25] cynic@php.net
1) you don't need mysql for this. any error message contains full path to the script.
2) this will only happen with display_errors on, which is _not_ recommended for production sites.
3) I don't think the zillions of PHP coder out there would be grateful if this
authoring/debugging convenience disappeared.
4) you can always write your own error handler that won't give out the path.
=> bogus
---------------------------------------------------------------------------
[2001-03-31 09:35:34] megahz@the-megahz.com
at the bugtraq yesterday:
I've found a bug in php/MySQL that can show u the webroot path.
If u ask a non-existent file:
http://xxx.xxx.xxx.xxx/comments.php?file=.3425
server's answer is:
Warning: 0 is not a MySQL result index in /www/lc/linstart/www/other_languages/german/comments.php
on line 74
I don't know if it's xploitable, I dont'know MySQL.
Let's xploit it!!
Darko
--------------
But this:
This will only happen if you have NOT turned off the error reporting in the
php.ini file. If you turn it off, and log the errors to a file you will not
get this.
---------------------------------------------------------------------------
ATTENTION! Do NOT reply to this email!
To reply, use the web interface found at http://bugs.php.net/?id=10091&edit=2