Return-Path: Delivered-To: apache-bugdb-archive@hyperreal.org Received: (qmail 27963 invoked by uid 6000); 10 Oct 1998 04:00:09 -0000 Received: (qmail 27751 invoked by uid 2001); 10 Oct 1998 04:00:01 -0000 Received: (qmail 26916 invoked by uid 2012); 10 Oct 1998 03:56:48 -0000 Message-Id: <19981010035648.26915.qmail@hyperreal.org> Date: 10 Oct 1998 03:56:48 -0000 From: Vitaliy Fuks Reply-To: deicide@gameaholic.com To: apbugs@hyperreal.org X-Send-Pr-Version: 3.2 Subject: other/3173: PR3071 - Confidential path information shown in error messages still present in 1.3.3 in 500 Internal Server Error messages Sender: apache-bugdb-owner@apache.org Precedence: bulk >Number: 3173 >Category: other >Synopsis: PR3071 - Confidential path information shown in error messages still present in 1.3.3 in 500 Internal Server Error messages >Confidential: no >Severity: serious >Priority: medium >Responsible: apache >State: open >Class: sw-bug >Submitter-Id: apache >Arrival-Date: Fri Oct 9 21:00:01 PDT 1998 >Last-Modified: >Originator: deicide@gameaholic.com >Organization: apache >Release: 1.3.3 >Environment: Linux shell.gameaholic.com 2.0.35 #6 Thu Aug 6 22:15:59 EDT 1998 i586 unknown gcc version 2.7.2.3 >Description: 500 Internal Server Error /usr/home/deicide/bluesnews/admin/.htaccess: Invalid command 'Auth_MYSQLdatabase', perhaps mis-spelled or defined by a module not included in the server configuration Disregard the error itself - pay attention to that full path of .htaccess is shown. >How-To-Repeat: Create an intentional 500 Error by creating a .htaccess file with random garbage in it. >Fix: Probably no file information should be show at all. >Audit-Trail: >Unformatted: [In order for any reply to be added to the PR database, ] [you need to include in the Cc line ] [and leave the subject line UNCHANGED. This is not done] [automatically because of the potential for mail loops. ] [If you do not include this Cc, your reply may be ig- ] [nored unless you are responding to an explicit request ] [from a developer. ] [Reply only with text; DO NOT SEND ATTACHMENTS! ]