Warning: file_get_contents(/nonexistent/path/to/file.txt): Failed to open stream: No such file or directory in /home/vulnlab.informatikaunimus.id/public_html/vulnerabilities/info-disclosure/index.php on line 52
Information Disclosure - VulnLab
← Back to Dashboard

🔴 Trigger Errors

Click buttons to trigger different error types and see verbose error messages:

PHP Error SQL Error File Error Type Error Division Error

📊 Exposed Information

phpinfo() Database Info

🖥️ Server Information

PHP Version: 8.3.17
Server Software: LiteSpeed
Document Root: /home/vulnlab.informatikaunimus.id/public_html
Script Path: /home/vulnlab.informatikaunimus.id/public_html/vulnerabilities/info-disclosure/index.php
OS: Linux

📁 Exposed Paths

include_path: .: extension_dir: /usr/local/lsws/lsphp83/lib/php/20230831 session.save_path: /var/lib/lsphp/session/lsphp83 upload_tmp_dir: default

🎯 Vulnerability Info

Type: Information Disclosure

Severity: Medium

💡 Information Exposed

  • PHP version and configuration
  • Database errors and queries
  • File paths and server structure
  • Stack traces revealing code flow
  • Installed extensions
  • Environment variables

⚠️ Why It's Dangerous

  • Helps attackers plan attacks
  • Reveals software versions (CVE lookup)
  • Exposes internal architecture
  • May leak sensitive configuration
  • Database connection details visible

🔧 What Attackers Look For

- PHP/Apache/MySQL versions - Installed modules - File paths structure - Database credentials - Session configuration - Disabled functions - Open ports - Environment variables

📝 Production Settings

In production, these should be set:

display_errors = Off display_startup_errors = Off log_errors = On error_log = /path/to/error.log expose_php = Off