BugTraq
PHP XSS exploit in phpinfo() Jun 03 2003 01:30PM
silent needle (silentneedle hotmail com) (1 replies)
Re: PHP XSS exploit in phpinfo() Jun 04 2003 07:05PM
Daniel Naber (daniel naber t-online de)
On Tuesday 03 June 2003 15:30, silent needle wrote:

> A: BACKGROUND(from php.net)
> int phpinfo ( [int what])
> Outputs a large amount of information about the current state of PHP.

And because of that amount of information it's a security issue if
phpinfo() is publically available at all, not just because you can do XSS
with it. (Of course it should be fixed anyway.)

Regards
Daniel

--
http://www.danielnaber.de

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus