Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHP Include File Relative Directory Information Disclosure Vulnerability

Apache is a powerful, widely used web server available for most operating systems, including Linux, Windows and many other Unix like systems. PHP is a widely deployed scripting language, designed for web based development and CGI programming.

A path disclosure vulnerability exists in the default configuration of some releases of PHP when used with the Apache web server. If PHP include files are references with a relative directory, it is possible to cause the include statement to fail. Submitting a request for a php file appended with a trailing slash '/', will return an error message and the full path to the include file directory.

'Require' statements may also be susceptible to this issue.







 

Privacy Statement
Copyright 2008, SecurityFocus