Version Disclosure (PHP)
Summary#
Invicti identified a version disclosure (PHP) in the target web server's HTTP response.
This information can help an attacker gain a greater understanding of the systems in use and potentially develop further attacks targeted at the specific version of PHP.
Impact#
An attacker might use the disclosed information to harvest specific security vulnerabilities for the version identified.
Remediation#
Configure your web server to prevent information leakage from the
SERVER
header of its HTTP response.
Classifications#
Invicti Security Insights
- Sven Morgenroth Talks About PHP Object Injection Vulnerabilities on Paul’s Security Weekly Podcast
- End of Support for PHP 5 and PHP 7.0
- PHP Wrappers, Streams & Local File Intrusion (LFI)
- Sven Morgenroth Talks About PHP Type Juggling on Paul’s Security Weekly Podcast
- PHP Type Juggling Exploit: Vulnerability, Payloads, and Fixes