Bug #14909 Updated: Allows access to ANY file

From: Date: Mon, 07 Jan 2002 14:41:20 +0000
Subject: Bug #14909 Updated: Allows access to ANY file
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-76186@lists.php.net to get a copy of this message
ID: 14909
Updated by: georg
Reported By: leighgardiner@hotmail.com
Old Status: Open
Status: Bogus
Bug Type: Apache related
Operating System: Windows
PHP Version: 4.1.1
New Comment:

Unbelievable, why do you set your cgi-binary in the document root
tree!?

See http://www.cert.org/advisories/CA-1996-11.html

Previous Comments:
------------------------------------------------------------------------

[2002-01-07 09:34:04] leighgardiner@hotmail.com

Well you should have already heard about this but I'll report it anyway
becoz we all need a fix very fast! Well when you do this:
http://www.example.com/php/php.exe?c:\winnt\repair\sam
  (this is an
example, you can view any file) it will return the files contents! This
happens with ANY windows versions...i don't think it affects linux. Also
this will return the install path of PHP:
http://www.example.com/php/php4ts.dll
could you please get a path/new vesion out ASAP! This is extremly
serious!

------------------------------------------------------------------------



Edit this bug report at http://bugs.php.net/?id=14909&edit=1



Thread (9 messages)

« previous php.dev (#76186) next »