Bug #13749 Updated: >?php instead of <?php displays password and user info

From: Date: Fri, 19 Oct 2001 12:56:33 +0000
Subject: Bug #13749 Updated: >?php instead of <?php displays password and user info
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-68370@lists.php.net to get a copy of this message
ID: 13749 Updated by: derick Reported By: malcolm@prebon.co.uk Old Status: Open Status: Bogus Bug Type: MySQL related Operating System: Linux PHP Version: 4.0.6 New Comment: PHP can not guard for typing errors. It's your own responsility. Not a bug > bogus. Derick Previous Comments: ------------------------------------------------------------------------ [2001-10-19 08:50:18] malcolm@prebon.co.uk If you have a script that talks to a MySQL db and includes an inc in another directory with the login part of the script and you mistype the start as >?php instead of <?php then php returns the text of the inc file ( which contains the ip address, username and password of the mysql server ) This is what the script returned ( with real info which I have removed ) <?xml version="1.0" encoding="ISO-8859-1" standalone="no"?> >?php # #dbconnect.inc # function &dbconnect() { $link=@mysql_connect ("172.nnn.nnn.nn","xxxxx","yyyyyy"); if ($link && mysql_select_db ("pwtdb")) { $dbok="True"; return $dbok; } else { $dbok="False"; return $dbok; } } ?><br> <b>Fatal error</b>: Call to undefined function: dbconnect() in <b>/usr/local/apache/htdocs/pwtvalidate.php</b> on line <b>37</b><br> ------------------------------------------------------------------------ Edit this bug report at http://bugs.php.net/?id=13749&edit=1

« previous php.dev (#68370) next »