|  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #19604 source.php has major security vulnerability
Submitted: 2002-09-25 17:54 UTC Modified: 2002-09-25 18:00 UTC
From: h3h at h3h dot net Assigned:
Status: Not a bug Package: Website problem
PHP Version: 4.2.3 OS: Windows 2000 SP3
Private report: No CVE-ID: None
View Add Comment Developer Edit
Anyone can comment on a bug. Have a simpler test case? Does it work for you on a different platform? Let us know!
Just going to say 'Me too!'? Don't clutter the database with that please !
Your email address:
Solve the problem:
1 + 30 = ?
Subscribe to this entry?

 [2002-09-25 17:54 UTC] h3h at h3h dot net
As I was writing my own source.php script, to basically accomplish the same task as the source.php file on, I noticed a significant vulnerability that was present on my system using this approach. In UNIX and Windows, ../ can be used to access the parent directory of the current working directory. Using this methodology, I was able to transcend above my web directory where the source.php file resides and into protected system files that should not otherwise be accessed. I tried to duplicate this behavior with the source.php script on and was successful. I believe that by continuing to use an arbitrary amount of '../' blocks in the url, any file currently on the server within the web server's permissions can be accessed without authorization. Case in point:
With that simple url, I have gained access to the .htaccess file that resides above the root web directory of
In my implementation of source.php, I simply checked for any occurence of '..' and denied access accordingly. There may be other exploitable commands along with this, however this is the only one that comes to mind.
My Source:
I hope this comes as a constructive bug report. Thanks.


Add a Patch

Pull Requests

Add a Pull Request


AllCommentsChangesGit/SVN commitsRelated reports
 [2002-09-25 18:00 UTC]
if you had read the source this just isn't a problem... we don't allow stuff outside of the docroot to be viewed.
PHP Copyright © 2001-2023 The PHP Group
All rights reserved.
Last updated: Sat Feb 04 00:03:40 2023 UTC