QID 730715
Date Published: 2023-02-01
QID 730715: Hypertext Preprocessor (PHP) Development Server Remote Source Disclosure Vulnerability
PHP development server prior to version 7.4.22 have a bug that can expose the source code of PHP files as if they were static files rather than executing them as intended.
Affected Versions:
PHP development server versions prior to 7.4.22.
QID Detection Logic (Unauthenticated): This QID checks for vulnerable instances of PHP development server by sending a crafted payload to the webserver.
Note: PHP files can be named anything depending on the web application. It is not feasible to detect all PHP files with our detections. This QID will only detect some common files such as index.php, phpinfo.php, admin.php, wp-config.php etc in the web root.
Successful exploitation of the vulnerability may allow remote attackers to view the source code of PHP files and steal sensitive information.
CVEs related to QID 730715
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| NA |
|