|
php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login |
PatchesPull RequestsHistoryAllCommentsChangesGit/SVN commits
[2019-09-20 08:02 UTC] requinix@php.net
-Status: Open
+Status: Not a bug
[2019-09-20 08:02 UTC] requinix@php.net
[2019-09-20 08:19 UTC] kalle@php.net
|
|||||||||||||||||||||||||||
Copyright © 2001-2025 The PHP GroupAll rights reserved. |
Last updated: Fri Oct 24 07:00:01 2025 UTC |
Description: ------------ Displaying error messages (filename) is vulnerable to XSS, We just need to set the name of a PHP file to something like this: <img src=x onerror=alert('XSS')>.php Test script: --------------- <img src=x onerror=alert('XSS')>.php: <?php $file = $_GET['f']; $f = fopen($file, 'r'); ?> Expected result: ---------------- When you open this file in your browser you will get 2 XSS popups.