The usual Nginx + PHP cgi setup sets SCRIPT_FILENAME in the config file with a regex match (The PATH_INFO Problem with Nginx (PHP/fastcgi)). Today Xiaodun found a security hole in this approach.
Say you have http://www.laruence.com/fake.jpg. Craft the following URL and you can see the binary contents of fake.jpg:
http://www.laruence.com/fake.jpg/foo.php
Why does that happen?
with 0 Comment