Home / Vulnerability Database / Config files : php.ini: Information leak
Config files

Config files : php.ini: Information leak

Overview

System configuration information leak is possible. This can help an attacker to plan an attack.

The debug information and error messages depending on the system settings can be written to the log, displayed in the console, or sent to the user. In some cases, an attacker can make a conclusion about the vulnerabilities of the system based on an error message. For example, a database error can indicate the insecurity against attacks such as SQL injection. Information about the version of the operating system, application server and system configuration can also be valuable to the attacker.

MEDIUM

DerScanner Severity Score

Do you want to fix Config files : php.ini: Information leak in your application?

See also

Config files

Config files : Text4Shell Vulnerability

Config files

Config files : Incorrect directory deletion

Config files

Config files : Code injection