From: t.bubeck@reinform.de
Operating system: Red Hat 7.1
PHP version: 4.2.2
PHP Bug Type: HTTP related
Bug description: no form variables after multipart/form-data
If you use a HTML form together with multipart/form-data encryption, then
the
browser will send the form data in a POST request surrounded with
boundaries.
Microsoft Internet Explorer (MSIE 5.0 at least) is violating the HTTP
specification (rfc 2616, paragraph 3.7: "Media Types") by repeating the
content-type in a wrong syntax. This will break PHP in looking for
boundaries
of the multiparts and therefore no global variables will be defined
containing
the form data. This will make it impossible to use PHP together with MSIE
to
process any form data encoded with "multipart/form-data". This results in
many
different bugs reported in large PHP projects (e.g. SquirrelMail) which
are
impossible to fix.
Here is the (broken) HTTP request of MSIE:
POST /squirrel/src/compose.php HTTP/1.0
Via: 1.0 NDCSTR16
Connection: Keep-Alive
Content-Length: 1889
User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT; DigExt)
Content-Type: multipart/form-data;
boundary=---------------------------7d29f1d3bad02b2,multipart/form-data;
boundary=---------------------------7d29f1d3bad02b2,multipart/form-data;
boundary=---------------------------7d29f1d3bad02b2
Host: reinform.hn.org
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg,
application/msword, application/vnd.ms-excel,
application/vnd.ms-powerpoint, */*
Accept-Language: de,de,de
Referer:
http://reinform.hn.org/squirrel/src/compose.php,http://reinform.hn.org/squirrel/src/compose.php,http://reinform.hn.org/squirrel/src/compose.php
Pragma: no-cache
Cookie: squirrelmail_language=de_DE; key=AW0RUMJgLK4%3D;
PHPSESSID=0afb8733761a1723a006ce1676d9aa7b
Accept-Encoding: gzip, deflate,gzip, deflate,gzip, deflate
-----------------------------7d29f1d3bad02b2
Content-Disposition: form-data; name="session"
7
-----------------------------7d29f1d3bad02b2
Content-Disposition: form-data; name="send_to"
-----------------------------7d29f1d3bad02b2
The wrong part is the Content-Type which contains more than a single
boundary
statement (which is a rfc2616 violation, because the parameters are not
seperated by ",").
PHP takes everything after the first '=' as the boundary and will
therefore
look for a boundary
"---------------------------7d29f1d3bad02b2,multipart/form-data;
boundary=---------------------------7d29f1d3bad02b2,multipart/form-data;
boundary=---------------------------7d29f1d3bad02b2" which is never found
in
the data stream. Therefore no parts are found and no variables are
declared.
The following (trivial) patch will fix the bug and is based upong the
current
CVS version of PHP-4.2.2:
diff -r -u php-4.2.2-orig/main/rfc1867.c php-4.2.2/main/rfc1867.c
--- php-4.2.2-orig/main/rfc1867.c Sat Jul 20 21:17:52 2002
+++ php-4.2.2/main/rfc1867.c Wed Aug 7 20:26:28 2002
@@ -599,7 +599,7 @@
SAPI_API SAPI_POST_HANDLER_FUNC(rfc1867_post_handler)
{
- char *boundary, *s=NULL, *start_arr=NULL, *array_index=NULL;
+ char *boundary, *boundary_end, *s=NULL, *start_arr=NULL,
*array_index=NULL;
char *temp_filename=NULL, *lbuf=NULL, *abuf=NULL;
int boundary_len=0, total_bytes=0, cancel_upload=0, is_arr_upload=0,
array_len=0, max_file_size=0;
zval *http_post_files=NULL;
@@ -620,6 +620,10 @@
sapi_module.sapi_error(E_WARNING, "Missing boundary in
multipart/form-data POST data");
return;
}
+ /* search for the end of the boundary */
+ boundary_end = strchr(boundary, ',');
+ if ( boundary_end ) *boundary_end = 0;
+
boundary++;
boundary_len = strlen(boundary);
Would you please apply the patch?
Thanks,
Till
+-------+-------------------------------------------------------------+
| | dr. tilmann bubeck reinform medien- und |
| rein | informationstechnologie AG |
| form | cell.: +49 (172) 8 84 29 72 koenigstrasse 80 |
| AG | fax : +49 (711) 7 22 77 34 70173 stuttgart / germany |
| | email: t.bubeck@reinform.de http://www.reinform.de |
+-------+-------------------------------------------------------------+
--
Edit bug report at http://bugs.php.net/?id=18792&edit=1
--
Fixed in CVS: http://bugs.php.net/fix.php?id=18792&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=18792&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=18792&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=18792&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=18792&r=support
Expected behavior: http://bugs.php.net/fix.php?id=18792&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=18792&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=18792&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=18792&r=globals