#45606 [Bgs]: FILTER_SANITIZE_NUMBER_INT filters returns "----" as an int

From: Date: Wed, 23 Jul 2008 18:17:57 +0000
Subject: #45606 [Bgs]: FILTER_SANITIZE_NUMBER_INT filters returns "----" as an int
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-127206@lists.php.net to get a copy of this message
ID: 45606 User updated by: php at displague dot com Reported By: php at displague dot com Status: Bogus Bug Type: Filter related Operating System: ubuntu intrepid PHP Version: 5.2.6 Assigned To: pajoye New Comment: > sanitize checks only if all characters used in a given > input can be part of an integer, float, etc Where does it say that? http://php.net/manual/en/intro.filter.php From what I could gather from the docs, filter_var should return: Returns the filtered data, or FALSE if the filter fails. and filter_input should return: Value of the requested variable on success, FALSE if the filter fails, or NULL if the variable_name variable is not set. If the flag FILTER_NULL_ON_FAILURE is used, it returns FALSE if the variable is not set and NULL if the filter fails. I understand that FILTER_VALIDATE_INT is not as stringent as FILTER_SANITIZE_NUMBER_INT, but given these input and return combinations: input return x.9 9 x-9 -9 x '' - - + + ++ ++ -- -- Then given the string, "<!-- test -->", how is a return value of "----" a valid INT with a minimum of 1? I assume a regular expression is behind this filter, and at the very least I expect that it needs to be updated to only match no more than one "-" or "+" only if it is followed by a "." or [0-9]. Possibly others depending on localization settings. It's not much of a validation filter as it exists currently. Previous Comments: ------------------------------------------------------------------------ [2008-07-23 16:55:10] pajoye@php.net The sanitize checks only if all characters used in a given input can be part of an integer, float, etc. If you like to have a strict validation, use FILTER_VALIDATE_INT (or other validating filters). ------------------------------------------------------------------------ [2008-07-23 16:47:52] php at displague dot com Description: ------------ In code where I use filter_input(INPUT_GET, 'id', FILTER_SANITIZE_NUMBER_INT, array('options'=>array('min_range'=>1))); a vulnerability scanner tried to supply a value of <!-- test --> to the id parameter of the page. This filter statement caused $id=='----'. Reproduce code: --------------- $t="<!-- test -->"; $v=filter_var($t, FILTER_SANITIZE_NUMBER_INT, array('options'=>array('min_range'=>1))); Expected result: ---------------- $v==false Actual result: -------------- $v=='----' ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=45606&edit=1

« previous php.bugs (#127206) next »