Full Disclosure mailing list archives

Re: Information Disclosure with Invision Board installation (fwd)


From: rossen () pcmania bg (Rossen)
Date: Wed, 25 Sep 2002 02:55:39 +0300

Basic jizt - Invision Board (all version) - installation guide copies
across phpinfo.php, a file which calls phpinfo().
Example;
http://blahblahblah.corp.com/phpinfo.php

Fortunately phpinfo() is disabled in safe mode, which is a must for a
"production server":

::::::::  Warning: phpinfo() has been disabled for security reasons in
/phpinfo.php on line 8  :::::::::


regards,
Rossen
<rossen () pcmania bg>




Current thread: