Bug #17799 Updated: Using $this->$variable_name inside object clears all variable values
| From: | sander@php.net | Date: | Mon, 17 Jun 2002 13:58:21 +0000 |
| Subject: | Bug #17799 Updated: Using $this->$variable_name inside object clears all variable values | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-10866@lists.php.net to get a copy of this message | ||
ID: 17799
Updated by: sander@php.net
Reported By: qdot@numberporn.com
-Status: Open
+Status: Feedback
-Bug Type: Unknown/Other Function
+Bug Type: Class/Object related
Operating System: Win XP Pro- Should be indep.
PHP Version: 4.2.1
New Comment:
Can't reproduce:
$ php -v
PHP 4.3.0-dev (cli), Copyright (c) 1997-2002 The PHP Group
Zend Engine v1.2.1, Copyright (c) 1998-2002 Zend Technologies
$ cat test.php
<?php
error_reporting(E_ALL);
class foo {
var $a = 'a';
var $b = 'b';
function foo() {
$this->$a = 'foo';
}
}
$foo = &new foo();
print_r($foo);
?>
$ php test.php
Notice: Undefined variable: a in test.php on line 8
foo Object
(
[a] => a
[b] => b
[] => foo
)
Can you provide a simple and selfcontained sample script that
reproduces the problem?
Previous Comments:
------------------------------------------------------------------------
[2002-06-17 08:40:34] qdot@numberporn.com
Summary: When accidently using the syntax $this->$variable_name in an
object to set a variable, all the variables in the object are set to
the value that is given. This seems like it could cause a serious
security issue.
Steps to reproduce:
1. Create an object with multiple class variables
2. Create an setVar function with the incorrect syntax
3. Instantiate a new variable in a script to the class and use the
setVar function. All variables in the object will now hold this value.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=17799&edit=1