Hello list! I want to warn you about Full path disclosure and Information Leakage vulnerabilities in PHPIDS. ------------------------- Affected products: ------------------------- Vulnerable are PHPIDS 0.6.5 and previous versions. ---------- Details: ---------- Full path disclosure (WASC-13): http://site/script.php?p=’ At sending of "attacking" request (such as with single quote) to any php-script at the site with PHPIDS the full path at the server is showing. http://site/phpids/lib/IDS/Log/File.php Information Leakage (WASC-13): http://site/phpids/lib/IDS/tmplogs/phpids_log.txt Leakage of the whole log. ------------ Timeline: ------------ 2011.01.05 - announced at my site. 2011.01.06 - informed developers. 2011.01.06 - received answer from developers. 2011.01.16 - I gave developers recommendations about fixing the holes. 2011.01.17 - developers fixed these holes (changeset 1446), but not all of them. 2011.01.19 - I informed developers, that FPD holes are fixed not completely. 2011.03.02 - disclosed at my site. I mentioned about these vulnerabilities at my site (http://websecurity.com.ua/4815/). Best wishes & regards, MustLive Administrator of Websecurity web site http://websecurity.com.ua