#43008 [Com]: php://filter uris ignore url encoded filternames and can't handle slashes
| From: | php at benjaminschulz dot com | Date: | Fri, 11 Jul 2008 19:37:10 +0000 |
| Subject: | #43008 [Com]: php://filter uris ignore url encoded filternames and can't handle slashes | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-126512@lists.php.net to get a copy of this message | ||
ID: 43008
Comment by: php at benjaminschulz dot com
Reported By: php at benjaminschulz dot com
Status: Assigned
Bug Type: Streams related
Operating System: linux
PHP Version: 5.3CVS-2007-10-17 (CVS)
Assigned To: hholzgra
New Comment:
The patch works perfectly for me.
Previous Comments:
------------------------------------------------------------------------
[2008-07-11 09:16:14] arnaud dot lb at gmail dot com
A possible fix would be to urldecode() filter names in the php://
wrapper before passing them to the filter API:
http://arnaud.lb.s3.amazonaws.com/url_encoded_filter-43008.patch
------------------------------------------------------------------------
[2008-03-17 23:42:28] php at benjaminschulz dot com
This should work because otherwise there is no way to pass valid and
existing filternames as URIs to PHP.
(This bug is approved by hartmut btw.)
------------------------------------------------------------------------
[2008-03-17 20:53:31] jani@php.net
And this should work because..? (IMO, it's expected, you pass invalid
data -> you get an error..simple.)
------------------------------------------------------------------------
[2008-03-10 14:55:17] php at benjaminschulz dot com
If the filtername is not URL encoded than i get this:
Warning: readfile(): unable to create or locate filter
"convert.iconv.ISO-8859-15" in ...
Warning: readfile(): Unable to create filter
(convert.iconv.ISO-8859-15) in ...
Warning: readfile(): unable to locate filter "UTF-8" in ...
Warning: readfile(): Unable to create filter (UTF-8) in ...
------------------------------------------------------------------------
[2007-10-17 17:04:40] php at benjaminschulz dot com
Description:
------------
because filternames can contain slashes (convert.iconv.from-enc/to-enc)
it should be possible to pass URL-encodet filternames to php://filter
Reproduce code:
---------------
<?php
$str =
'php://filter/read=convert.iconv.ISO-8859-15%2FUTF-8/resource=data://text/plain,foobar';
^ url encoded slash
Expected result:
----------------
string(6) "foobar"
Actual result:
--------------
Warning: file_get_contents(): unable to create or locate filter
"convert.iconv.ISO-8859-15%2FUTF-8" in /var/www/foo/a.php on line 34
Warning: file_get_contents(): Unable to create filter
(convert.iconv.ISO-8859-15%2FUTF-8) in /var/www/foo/a.php on line 34
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=43008&edit=1