PHP3 Physical Path Disclosure via POST Requests

medium Nessus Plugin ID 10670

Synopsis

The remote server is affected by an information disclosure vulnerability.

Description

The version of PHP3 running on the remote host will reveal the physical path of a given script when sent a HTTP POST request without a content-type header if it is incorrectly configured.

Solution

In the PHP configuration file, change display_errors to 'Off' or upgrade to an unaffected PHP version.

See Also

https://seclists.org/bugtraq/2000/Jun/226

Plugin Details

Severity: Medium

ID: 10670

File Name: php3_path_disclosure.nasl

Version: 1.25

Type: remote

Family: CGI abuses

Published: 2/27/2015

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: cpe:/a:php:php

Required KB Items: www/PHP

Vulnerability Publication Date: 5/14/2001