Bug #17799: Using $this->$variable_name inside object clears all variable values
| From: | qdot at numberporn dot com | Date: | Mon, 17 Jun 2002 12:40:34 +0000 |
| Subject: | Bug #17799: Using $this->$variable_name inside object clears all variable values | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-10856@lists.php.net to get a copy of this message | ||
From: qdot@numberporn.com
Operating system: Win XP Pro- Should be indep.
PHP version: 4.2.1
PHP Bug Type: Unknown/Other Function
Bug description: Using $this->$variable_name inside object clears all variable values
Summary: When accidently using the syntax $this->$variable_name in an
object to set a variable, all the variables in the object are set to the
value that is given. This seems like it could cause a serious security
issue.
Steps to reproduce:
1. Create an object with multiple class variables
2. Create an setVar function with the incorrect syntax
3. Instantiate a new variable in a script to the class and use the setVar
function. All variables in the object will now hold this value.
--
Edit bug report at http://bugs.php.net/?id=17799&edit=1
--
Fixed in CVS: http://bugs.php.net/fix.php?id=17799&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=17799&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=17799&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=17799&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=17799&r=support
Expected behavior: http://bugs.php.net/fix.php?id=17799&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=17799&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=17799&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=17799&r=globals