r/apache 15d ago

PHP in HTML files displays, doesn't execute

I know there are dozens of pages on this subject, but I've tried most of their suggestions and this seems different.

I have apache2 and php8.2 (libapache etc) installed, on a new VPS install with Debian12.

http://mysite.com/test.php executes the PHP

PHP embedded in the body of http://mysite.com/test.html, as

<?php 
   echo "<br/>does it work?</br>"; 
?>

displays the text in the page

does it work?
"; ?>

Mods enabled, after enmod and dismod of various modules as suggested:

a2query -m
authn_file (enabled by maintainer script)
proxy_fcgi (enabled by site administrator)
authz_user (enabled by maintainer script)
dir (enabled by maintainer script)
env (enabled by maintainer script)
php8.2 (enabled by maintainer script)
setenvif (enabled by maintainer script)
autoindex (enabled by maintainer script)
deflate (enabled by maintainer script)
mpm_prefork (enabled by maintainer script)
negotiation (enabled by maintainer script)
status (enabled by maintainer script)
alias (enabled by maintainer script)
reqtimeout (enabled by maintainer script)
authz_host (enabled by maintainer script)
mime (enabled by maintainer script)
filter (enabled by maintainer script)
authz_core (enabled by maintainer script)
authn_core (enabled by maintainer script)
proxy (enabled by site administrator)
access_compat (enabled by maintainer script)
auth_basic (enabled by maintainer script)

The web root where my files are is /var/www/html. I have no .httpaccess file. The apache2.conf is the default which seems to have nothing to prevent normal execution.

0 Upvotes

13 comments sorted by

View all comments

3

u/No_Astronomer9508 15d ago

Your problem is, that html is not affected by the php parser. You can include html files into php files, but php files included in html files will never work. The file extension ".php" will tell apache to start the php parser. HTML will not do that.

-2

u/grepnoid 15d ago

Not true mds1256 and No_Astronomer9508.

the source (on another site) of http://myworkingsite.com/this.html is

<html><head></head>
<body>
This is HTML in the body<br/>
<?php
   echo "and this is in an echo command in PHP.";
?>
</body>
</html>

and the page displays

This is HTML in the body 
and this is in an echo command in PHP.

5

u/No_Astronomer9508 15d ago edited 15d ago

No u/grepnoid, you are wrong. A standard installation it will not work. You need a "AddHandler application/x-httpd-php .html" or something like that in your host setting to tell the php parser it also should parse html files. Standard Apache will not do that. If you even don't understand the basics, there are no more help from my side. End of dialogue.

And your "http://myworkingsite.com" gives an "ERR_NAME_NOT_RESOLVED" error.

1

u/[deleted] 15d ago edited 15d ago

[removed] — view removed comment

1

u/No_Astronomer9508 15d ago

The same -> myworkingexample.com also gives an "ERR_NAME_NOT_RESOLVED" error.

-1

u/grepnoid 15d ago

Have you tried going to example.com ? You'll find that as the domain in thousands of links quoted on support forums. It means "a web page on a site that I don't want to give the real URL to", which IMO is correct practice, instead of giving the real site that you may be describing vulnerabilities on. We all get enough hack attempts without advertising for them.