RE: Bug #13749 Updated: >?php instead of <?php displays password and user info

From: Date: Fri, 19 Oct 2001 13:28:18 +0000
Subject: RE: Bug #13749 Updated: >?php instead of <?php displays password and user info
Groups: php.dev 
Request: Send a blank email to php-dev+get-68373@lists.php.net to get a copy of this message
I would have hoped that a reversed < wouldn't have displayed the user name
and password

best wishes

mal 

-----Original Message-----
From: Bug Database [mailto:php-dev@lists.php.net]
Sent: 19 October 2001 13:57
To: malcolm@prebon.co.uk
Subject: Bug #13749 Updated: >?php instead of <?php displays password
and user info


ID: 13749
Updated by: derick
Reported By: malcolm@prebon.co.uk
Old Status: Open
Status: Bogus
Bug Type: MySQL related
Operating System: Linux
PHP Version: 4.0.6
New Comment:

PHP can not guard for typing errors. It's your own responsility.
Not a bug > bogus.

Derick

Previous Comments:
------------------------------------------------------------------------

[2001-10-19 08:50:18] malcolm@prebon.co.uk

If you have a script that talks to a MySQL db and includes an inc in another
directory with the login part of the script and you mistype the start as
>?php instead of <?php then php returns the text of the inc file ( which
contains the ip address, username and password of the mysql server )
This is what the script returned ( with real info which I have removed )

<?xml version="1.0" encoding="ISO-8859-1" standalone="no"?>
>?php
#
#dbconnect.inc
#
function &dbconnect()
{
	$link=@mysql_connect ("172.nnn.nnn.nn","xxxxx","yyyyyy");
	if ($link && mysql_select_db ("pwtdb"))
	{
		$dbok="True";
		return $dbok;
	}
	else
	{
		$dbok="False";
		return $dbok;
	}
}
?><br>
<b>Fatal error</b>:  Call to undefined function:  dbconnect() in
<b>/usr/local/apache/htdocs/pwtvalidate.php</b> on line <b>37</b><br>




------------------------------------------------------------------------



ATTENTION! Do NOT reply to this email!
To reply, use the web interface found at
http://bugs.php.net/?id=13749&edit=2


**********************************************************************
This email is intended only for the addressee. This email
and any files transmitted with it may contain confidential
or privileged information. If you are not the named
addressee or the person responsible for delivering the
message to the named addressee, please contact 
postmasters@prebon.co.uk

This email has been scanned by MIMEsweeper.

Visit the Prebon Marshall Yamane web site at 
http://www.prebon.com
**********************************************************************


Thread (5 messages)

« previous php.dev (#68373) next »