PHP and Wordpress version disclosure

Disclosed: 2014-06-11 08:56:57 By siddiki To iandunn-projects
Unknown
Vulnerability Details
**Vulnerable File** google-authenticator-per-user-prompt/views/requirements-error.php **Description** That file discloses the PHP version and Wordpress version to the world.Which is not a bug actually,but these information can be helpful to demonstrate further devastating bugs. **Suggestion** I saw that you rejected many path disclosure reports cause those are not in your hand.It depends upon server settings,how that will handle error messages.But this case is different.Its not actually an error message.And cant be mitigated by switching off error display. I suggest you to keep such actions so that unauthorized users could not use this file directly.
Actions
View on HackerOne
Report Stats
  • Report ID: 9516
  • State: Closed
  • Substate: informative
  • Upvotes: 2
Share this report