#45606 [Opn->Bgs]: FILTER_SANITIZE_NUMBER_INT filters returns "----" as an int
| From: | pajoye@php.net | Date: | Wed, 23 Jul 2008 16:55:11 +0000 |
| Subject: | #45606 [Opn->Bgs]: FILTER_SANITIZE_NUMBER_INT filters returns "----" as an int | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-127205@lists.php.net to get a copy of this message | ||
ID: 45606
Updated by: pajoye@php.net
Reported By: php at displague dot com
-Status: Open
+Status: Bogus
Bug Type: Filter related
Operating System: ubuntu intrepid
PHP Version: 5.2.6
-Assigned To:
+Assigned To: pajoye
New Comment:
The sanitize checks only if all characters used in a given input can be
part of an integer, float, etc. If you like to have a strict validation,
use FILTER_VALIDATE_INT (or other validating filters).
Previous Comments:
------------------------------------------------------------------------
[2008-07-23 16:47:52] php at displague dot com
Description:
------------
In code where I use
filter_input(INPUT_GET, 'id', FILTER_SANITIZE_NUMBER_INT,
array('options'=>array('min_range'=>1)));
a vulnerability scanner tried to supply a value of <!-- test --> to the
id parameter of the page.
This filter statement caused $id=='----'.
Reproduce code:
---------------
$t="<!-- test -->";
$v=filter_var($t, FILTER_SANITIZE_NUMBER_INT,
array('options'=>array('min_range'=>1)));
Expected result:
----------------
$v==false
Actual result:
--------------
$v=='----'
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=45606&edit=1