#18727 [NEW]: XSS in I/O Function Output
| From: | mattmurphy at kc dot rr dot com | Date: | Sat, 03 Aug 2002 19:40:38 +0000 |
| Subject: | #18727 [NEW]: XSS in I/O Function Output | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-15929@lists.php.net to get a copy of this message | ||
From: mattmurphy@kc.rr.com
Operating system: Win32
PHP version: 4.2.2
PHP Bug Type: Output Control
Bug description: XSS in I/O Function Output
This applies to any PHP script that opens files based on some kind of
user-input inserted into the file name. If the file open fails, PHP
returns a warning. In that warning is the file name that was input. If
the user-input were to contain a specially crafted piece of data,
arbitrary code could be executed:
<?php
$handle = fopen("C:\\INETPUB\\WWWROOT\\" . $_GET["resource"], "rb");
?>
http://localhost/fopen.php?resource={SCRIPT}alert('xss'){/SCRIPT}
Replace "{" with "<" and "}" with ">" and you are
ready to go. When you
hit the enter key, the browser urlencodes the malicious string, and PHP
attempts to open the file, resulting in the vulnerability.
Solution
fopen() should *not* return the file name in raw form to the browser.
--
Edit bug report at http://bugs.php.net/?id=18727&edit=1
--
Fixed in CVS: http://bugs.php.net/fix.php?id=18727&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=18727&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=18727&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=18727&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=18727&r=support
Expected behavior: http://bugs.php.net/fix.php?id=18727&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=18727&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=18727&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=18727&r=globals