php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #76089 I can show and discover the server side script
Submitted: 2018-03-13 12:22 UTC Modified: 2018-03-13 12:38 UTC
From: gergelymolnarpro at gmail dot com Assigned: cmb (profile)
Status: Not a bug Package: Website problem
PHP Version: Irrelevant OS:
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: gergelymolnarpro at gmail dot com
New email:
PHP Version: OS:

 

 [2018-03-13 12:22 UTC] gergelymolnarpro at gmail dot com
Description:
------------
I can show and discover the server side script code with a simple http request at http://php.net
Example: http://php.net/cached.php?f=/index.php
Example2: http://php.net/cached.php?f=/include/prepend.inc


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2018-03-13 12:24 UTC] gergelymolnarpro at gmail dot com
If it is closed and fixed, can I report that at hackerone.com?
 [2018-03-13 12:38 UTC] cmb@php.net
-Status: Open +Status: Not a bug -Assigned To: +Assigned To: cmb
 [2018-03-13 12:38 UTC] cmb@php.net
The code is publicly available anyway[1], so there is no bug.

[1] <https://github.com/php/web-php/blob/master/index.php>
    <https://github.com/php/web-php/blob/master/include/prepend.inc>
 [2018-03-13 12:46 UTC] gergelymolnarpro at gmail dot com
Sorry for report that. I thought I found a nice bug...
 
PHP Copyright © 2001-2025 The PHP Group
All rights reserved.
Last updated: Tue Jul 01 21:01:35 2025 UTC