|
Save the teapot fund New CSS web design for Wibble proudly provided by Kelv. Please contact the webmaster with any questions or concerns. |
Wibble > List archives > bugtraq > 2003 [Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: PHP XSS exploit in phpinfo()
On Tuesday 03 June 2003 15:30, silent needle wrote: > A: BACKGROUND(from php.net) > int phpinfo ( [int what]) > Outputs a large amount of information about the current state of PHP. And because of that amount of information it's a security issue if phpinfo() is publically available at all, not just because you can do XSS with it. (Of course it should be fixed anyway.) Regards Daniel -- http://www.danielnaber.de
|