#45606 [Opn->Bgs]: FILTER_SANITIZE_NUMBER_INT filters returns "----" as an int

From: Date: Wed, 23 Jul 2008 16:55:11 +0000
Subject: #45606 [Opn->Bgs]: FILTER_SANITIZE_NUMBER_INT filters returns "----" as an int
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-127205@lists.php.net to get a copy of this message
ID: 45606 Updated by: pajoye@php.net Reported By: php at displague dot com -Status: Open +Status: Bogus Bug Type: Filter related Operating System: ubuntu intrepid PHP Version: 5.2.6 -Assigned To: +Assigned To: pajoye New Comment: The sanitize checks only if all characters used in a given input can be part of an integer, float, etc. If you like to have a strict validation, use FILTER_VALIDATE_INT (or other validating filters). Previous Comments: ------------------------------------------------------------------------ [2008-07-23 16:47:52] php at displague dot com Description: ------------ In code where I use filter_input(INPUT_GET, 'id', FILTER_SANITIZE_NUMBER_INT, array('options'=>array('min_range'=>1))); a vulnerability scanner tried to supply a value of <!-- test --> to the id parameter of the page. This filter statement caused $id=='----'. Reproduce code: --------------- $t="<!-- test -->"; $v=filter_var($t, FILTER_SANITIZE_NUMBER_INT, array('options'=>array('min_range'=>1))); Expected result: ---------------- $v==false Actual result: -------------- $v=='----' ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=45606&edit=1

« previous php.bugs (#127205) next »