Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> CGI abuses >> PHP3 Physical Path Disclosure Vulnerability


Vulnerability Assessment Details

PHP3 Physical Path Disclosure Vulnerability

Vulnerability Assessment Summary
Tests for PHP3 Physical Path Disclosure Vulnerability

Detailed Explanation for this Vulnerability Assessment
PHP3 will reveal the physical path of the
webroot when asked for a non-existent PHP3 file
if it is incorrectly configured. Although printing errors
to the output is useful for debugging applications, this
feature should not be enabled on production servers.

Solution :
In the PHP configuration file change display_errors to 'Off':
display_errors = Off

Reference : http://online.securityfocus.com/archive/1/65078
Reference : http://online.securityfocus.com/archive/101/184240

Network Security Threat Level: Low

Networks Security ID:

Vulnerability Assessment Copyright: This script is Copyright (C) 2001 Matt Moore

Cables, Connectors

SMS200S3/120G Kingston 120G 120GB Solid State Drive MLC Laptop SSD Durable N0D7
$74.96
SMS200S3/120G Kingston 120G 120GB Solid State Drive MLC Laptop SSD Durable N0D7 picturePatriot Pyro 240GB 2,5" SATA III SSD Solid State Drive 6 Gb/s PP240GS25SSDR
$64.99
Patriot Pyro 240GB 2,5SANDISK X210 512GB 6GBPS SATA 2.5'' SSD SOLID STATE DRIVE SD6SB2M-512G-1006
$9.99
SANDISK X210 512GB 6GBPS SATA 2.5'' SSD SOLID STATE DRIVE SD6SB2M-512G-1006  pictureMSI MS-16H2 GS60 Toshiba 128GB SSD Solid State Drive SATA 6gb/s THNSNH128G8NT
$54.99
MSI MS-16H2 GS60 Toshiba 128GB SSD Solid State Drive SATA 6gb/s THNSNH128G8NT  picture


Discussions

No Discussions have been posted on this vulnerability.