#18727 [Opn->Bgs]: XSS in I/O Function Output
| From: | cynic@php.net | Date: | Sat, 03 Aug 2002 20:17:19 +0000 |
| Subject: | #18727 [Opn->Bgs]: XSS in I/O Function Output | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-15934@lists.php.net to get a copy of this message | ||
ID: 18727
Updated by: cynic@php.net
Reported By: mattmurphy@kc.rr.com
-Status: Open
+Status: Bogus
Bug Type: Output Control
Operating System: Win32
PHP Version: 4.2.2
New Comment:
it's the programmer's responsibility to prevent such attacks.
i for one surely wouldn't want php muck with the error output while
writing some quick scripts. in larger applications, you need custom
error
handler and/or display_errors = off anyway.
so what's the deal?
Previous Comments:
------------------------------------------------------------------------
[2002-08-03 16:11:01] mattmurphy@kc.rr.com
Once again, I'm astounded by the overwhelmingly negative message that
the PHP Group sends users of PHP sites -- thanks to us, somebody can
steal your personal information! Oh, and, thanks for your business.
That is at least counter-productive, yes?
------------------------------------------------------------------------
[2002-08-03 16:00:54] sander@php.net
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
------------------------------------------------------------------------
[2002-08-03 15:40:37] mattmurphy@kc.rr.com
This applies to any PHP script that opens files based on some kind of
user-input inserted into the file name. If the file open fails, PHP
returns a warning. In that warning is the file name that was input.
If the user-input were to contain a specially crafted piece of data,
arbitrary code could be executed:
<?php
$handle = fopen("C:\\INETPUB\\WWWROOT\\" . $_GET["resource"], "rb");
?>
http://localhost/fopen.php?resource={SCRIPT}alert('xss'){/SCRIPT}
Replace "{" with "<" and "}" with ">" and you are
ready to go. When
you hit the enter key, the browser urlencodes the malicious string, and
PHP attempts to open the file, resulting in the vulnerability.
Solution
fopen() should *not* return the file name in raw form to the browser.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=18727&edit=1