#46759 [Csd]: magic_quotes_gpc doesn't work

From: Date: Sat, 06 Dec 2008 17:54:25 +0000
Subject: #46759 [Csd]: magic_quotes_gpc doesn't work
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-131691@lists.php.net to get a copy of this message
ID: 46759 Updated by: lbarnaud@php.net Reported By: vrana@php.net Status: Closed Bug Type: Variables related Operating System: Windows PHP Version: 5.2.7 New Comment: A quick workaround for 5.2.7 users is to add the following in the php.ini: filter.default_flags=0 Previous Comments: ------------------------------------------------------------------------ [2008-12-06 17:26:39] scottmac@php.net This bug has been fixed in CVS. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. Thank you for the report, and for helping us make PHP better. I've backed out the fix for bug #42718 ------------------------------------------------------------------------ [2008-12-06 17:08:43] magicaltux@php.net After checking bug #42718 and filter extension's documentation, I believe enabling a filter *should not* disable magic_quotes_gpc (nothing is written in the documentation about this). This patch allows application of magic_quotes_gpc *after* filters execution *if* enabled. http://ookoo.org/svn/snip/php_5_2-broken_filter_and_magic_quotes.patch ------------------------------------------------------------------------ [2008-12-06 16:20:04] magicaltux@php.net Fix for bug #42718 seems at the origin of this bug. If the fix is reverted, magic_quotes_gpc works again as expected. ------------------------------------------------------------------------ [2008-12-06 10:03:18] cabel at panic dot com We haven't yet had a chance to addslashes() our input in preparation for PHP 6. So as it stands, this bug -- which we're also seeing with 5.2.7 -- currently means giant scary security holes in our scripts as we were relying on magic_quotes_gpc to make things "safe". Not great... ------------------------------------------------------------------------ [2008-12-06 01:28:00] brion at pobox dot com This causes downstream MediaWiki bug: https://bugzilla.wikimedia.org/show_bug.cgi?id=16570 Data corruption and failure to properly submit edits when magic_quotes_gpc is enabled. (Workaround: disable magic_quotes_gpc so input doesn't get munged by stripslashes().) Presumably causes similar breakage in every other web app that attempts to correct for magic_quotes_gpc. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/46759 -- Edit this bug report at http://bugs.php.net/?id=46759&edit=1

« previous php.bugs (#131691) next »