|  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Sec Bug #65790 Deployment of xhprof_html makes the site vulnerable to XSS attack
Submitted: 2013-09-30 14:55 UTC Modified: 2013-10-01 13:52 UTC
From: spaze at exploited dot cz Assigned: scottmac (profile)
Status: Closed Package: xhprof (PECL)
PHP Version: Irrelevant OS:
Private report: No CVE-ID: None
View Add Comment Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
You can add a comment by following this link or if you reported this bug, you can edit this bug over here.
Block user comment
Status: Assign to:
Bug Type:
From: spaze at exploited dot cz
New email:
PHP Version: OS:


 [2013-09-30 14:55 UTC] spaze at exploited dot cz
When the xhprof_html directory is deployed it makes the site vulnerable to a Reflected XSS attack by not properly escaping the run parameter.

1. find a site with a xhprof_html deployed
2. change the run parameter to include <script>...</script> (e.g. /xhprof/?run=%3Cscript%3Ealert('XSS');%3C/script%3E)
3. load the page
4. notice the JS alert

NB: XSS filters in some browsers might block this attack

Expected result:
JavaScript is not executed, input is properly sanitized and/or escaped.

Actual result:
JavaScript is executed in the context of the user visiting the page.


Add a Patch

Pull Requests

Add a Pull Request


AllCommentsChangesGit/SVN commitsRelated reports
 [2013-09-30 15:10 UTC]
If that page is public one has other issues, too. This should be fixed nonetheless, I'll contact xhprof maintainers.
 [2013-09-30 16:21 UTC]
-Status: Open +Status: Closed -Assigned To: +Assigned To: scottmac
 [2013-09-30 16:43 UTC] spaze at exploited dot cz
Unfortunately, the commit didn't make it to 0.9.3 available from
 [2013-09-30 21:28 UTC]
-Status: Closed +Status: Assigned
 [2013-09-30 21:28 UTC]
I can confirm this changeset is not in the release. Scott, any chance for a new release?
 [2013-10-01 13:52 UTC]
-Status: Assigned +Status: Closed
 [2013-10-01 13:52 UTC]
Scott released a new version. This issue should be fixed.
PHP Copyright © 2001-2020 The PHP Group
All rights reserved.
Last updated: Wed Jan 29 16:01:25 2020 UTC