Menu

#10 Security hole, configfiles can be viewed

open
nobody
None
5
2002-07-30
2002-07-30
Anonymous
No

Because the configfiles are called *.inc they will not be
parsed by php.

for example http://url/myphpim/conf/config.inc will show
all the settings, also username and password for
myphpim. There is a .htaccess file, but on some servers
htaccess isn't configured and then the files ar visible.

Discussion


Log in to post a comment.

Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.