Uploaded image for project: 'phpBB'
  1. phpBB
  2. PHPBB-9359

SQL error message also given if DEBUG-mode disabled

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Won't Fix
    • Icon: Major Major
    • 3.0.15-RC1
    • 3.0.x
    • Other
    • None

      Don't know whether this is by design or not: the complete SQL error message including parts of the faulty SQL statement is given to all users even if DEBUG-mode is disabled. This might give an attacker some information about potential issues with faulty modifications.

            CHItA CHItA
            PhilippK PhilippK [X] (Inactive)
            Votes:
            1 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: