Bug #17799: Using $this->$variable_name inside object clears all variable values

From: Date: Mon, 17 Jun 2002 12:40:34 +0000
Subject: Bug #17799: Using $this->$variable_name inside object clears all variable values
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-10856@lists.php.net to get a copy of this message
From: qdot@numberporn.com Operating system: Win XP Pro- Should be indep. PHP version: 4.2.1 PHP Bug Type: Unknown/Other Function Bug description: Using $this->$variable_name inside object clears all variable values Summary: When accidently using the syntax $this->$variable_name in an object to set a variable, all the variables in the object are set to the value that is given. This seems like it could cause a serious security issue. Steps to reproduce: 1. Create an object with multiple class variables 2. Create an setVar function with the incorrect syntax 3. Instantiate a new variable in a script to the class and use the setVar function. All variables in the object will now hold this value. -- Edit bug report at http://bugs.php.net/?id=17799&edit=1 -- Fixed in CVS: http://bugs.php.net/fix.php?id=17799&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=17799&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=17799&r=needtrace Try newer version: http://bugs.php.net/fix.php?id=17799&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=17799&r=support Expected behavior: http://bugs.php.net/fix.php?id=17799&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=17799&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=17799&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=17799&r=globals

« previous php.bugs (#10856) next »