Support

Admin Tools

#31166 Qualys path disclosure

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Sunday, 28 April 2019 17:17 CDT

rbirbi
Hi,
I have bought your pro version. Works very nicely , thank you.
My company uses Qualys for vulnerability scan. Qualys is reporting several Path disclosure including for the home page at the root. I have spent hours in trying to understand what is wrong but I am out of ideas.
Maybe that you have suggestions please. I have attached a jpeg with an extract of example of 3 scan path vulnerability, and my htaccess.
Best regards
Roland

nicholas
Akeeba Staff
Manager
Without knowing the contents of the page nobody can possibly tell you if it's a false alarm or a legitimate issue. In either case, path disclosure is the result of a bug in the software running on your site, causing a full filesystem path to be displayed in the page's contents. Typically it's the result of a bug in the software and your Error Reporting in Global Configuration set to a value other than None. In this case PHP prints out an error message which includes the full filesystem path to the file where the error occurred.

Even so, your issue is unrelated to our software or the .htaccess file that you sent us. We are not responsible for third party software's bugs or your server's error reporting settings. The only two valid mitigations are 1. set the error reporting to None (the ONLY recommended value for live sites) and 2. find the problem causing the PHP error that's being printed out and contact its developer about a fix.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

rbirbi
Thanks Nicholas.
Issue is unrelated to your software because it was present before, sorry I did not mention that. I was asking for advice thanks to your expertise.
Thanks for your ideas. The Error Reporting in Global Configuration was already set to none. When I set it to normal I have php warnings but no errors. Can this warnings be the cause although the Error Reporting in Global Configuration is set to none ? Would you have other ideas ?

nicholas
Akeeba Staff
Manager
Without seeing the contents of the page I cannot tell you whether it's a false positive or whether there is something to it. Most likely it's the former, based on my experience with many site scanning services, but I cannot give a definitive answer without knowing the contents of the page.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!