Alan - Vox
01-10-2001, 04:32 PM
After logging into the admin control panel on my raq4 server if i goto a php gage with the phpinfo command in it, it displays my servers username and password.
Here is the info it displays
HTTP_SERVER_VARS["PHP_SELF"] /vblite/admin/test.php
HTTP_SERVER_VARS["PHP_AUTH_USER"] admin
HTTP_SERVER_VARS["PHP_AUTH_PW"] mypassword (this is not my password!!)
Do you think this could be a big security bug?
Does the same happen on other servers?
Here is the info it displays
HTTP_SERVER_VARS["PHP_SELF"] /vblite/admin/test.php
HTTP_SERVER_VARS["PHP_AUTH_USER"] admin
HTTP_SERVER_VARS["PHP_AUTH_PW"] mypassword (this is not my password!!)
Do you think this could be a big security bug?
Does the same happen on other servers?
