Bug #14909 Updated: Allows access to ANY file

From: Date: Mon, 07 Jan 2002 14:46:59 +0000
Subject: Bug #14909 Updated: Allows access to ANY file
References: 1  Groups: php.dev php.doc 
Request: Send a blank email to php-dev+get-76187@lists.php.net to get a copy of this message
ID: 14909
Updated by: imajes
Reported By: leighgardiner@hotmail.com
Old Status: Bogus
Status: Open
Old Bug Type: Apache related
Bug Type: Documentation problem
Operating System: Windows
PHP Version: 4.1.1
Old Assigned To: 
Assigned To: imajes@php.net
New Comment:

Actually, our documentation tells win32 users to install that way. I'm
investigating a better method right now, and will patch the
documentation in a short while.

I knew i forgot to do something after i updated my win32 last week!

Previous Comments:
------------------------------------------------------------------------

[2002-01-07 09:41:20] georg@php.net

Unbelievable, why do you set your cgi-binary in the document root
tree!?

See http://www.cert.org/advisories/CA-1996-11.html

------------------------------------------------------------------------

[2002-01-07 09:34:04] leighgardiner@hotmail.com

Well you should have already heard about this but I'll report it anyway
becoz we all need a fix very fast! Well when you do this:
http://www.example.com/php/php.exe?c:\winnt\repair\sam
  (this is an
example, you can view any file) it will return the files contents! This
happens with ANY windows versions...i don't think it affects linux. Also
this will return the install path of PHP:
http://www.example.com/php/php4ts.dll
could you please get a path/new vesion out ASAP! This is extremly
serious!

------------------------------------------------------------------------



Edit this bug report at http://bugs.php.net/?id=14909&edit=1



Thread (9 messages)

« previous php.dev (#76187) next »