|
php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login |
PatchesPull RequestsHistoryAllCommentsChangesGit/SVN commits
[2002-12-02 02:31 UTC] sesser@php.net
|
|||||||||||||||||||||||||||
Copyright © 2001-2026 The PHP GroupAll rights reserved. |
Last updated: Wed Feb 04 19:00:01 2026 UTC |
On all Servers we administrate, we always install an 'info.php' file which only contains the phpinfo() function. Now I found that PHP returns the transmitted password in clear text to the browser. The page is stored in the browsers cache or someone could just have a look on my screen. :-(( I think this is a serious security hole. The password should not be returned to the browser in any way, best would be to show some asterisks ('*******'), to show that the variable exists. Ulrich Kapp