#18792 [Ctl]: no form variables after multipart/form-data

From: Date: Wed, 07 Aug 2002 18:57:50 +0000
Subject: #18792 [Ctl]: no form variables after multipart/form-data
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-16200@lists.php.net to get a copy of this message
ID: 18792 Updated by: rasmus@php.net Reported By: t.bubeck@reinform.de Status: Critical Bug Type: HTTP related Operating System: Red Hat 7.1 PHP Version: 4.2.2 New Comment: Critical? Is this not fixed in CVS? I certainly can't reproduce it here. Previous Comments: ------------------------------------------------------------------------ [2002-08-07 14:56:36] sander@php.net Status -> critical Can someone with more insight to the POST mechanism in PHP look into this? ------------------------------------------------------------------------ [2002-08-07 14:50:35] t.bubeck@reinform.de If you use a HTML form together with multipart/form-data encryption, then the browser will send the form data in a POST request surrounded with boundaries. Microsoft Internet Explorer (MSIE 5.0 at least) is violating the HTTP specification (rfc 2616, paragraph 3.7: "Media Types") by repeating the content-type in a wrong syntax. This will break PHP in looking for boundaries of the multiparts and therefore no global variables will be defined containing the form data. This will make it impossible to use PHP together with MSIE to process any form data encoded with "multipart/form-data". This results in many different bugs reported in large PHP projects (e.g. SquirrelMail) which are impossible to fix. Here is the (broken) HTTP request of MSIE: POST /squirrel/src/compose.php HTTP/1.0 Via: 1.0 NDCSTR16 Connection: Keep-Alive Content-Length: 1889 User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT; DigExt) Content-Type: multipart/form-data; boundary=---------------------------7d29f1d3bad02b2,multipart/form-data; boundary=---------------------------7d29f1d3bad02b2,multipart/form-data; boundary=---------------------------7d29f1d3bad02b2 Host: reinform.hn.org Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/msword, application/vnd.ms-excel, application/vnd.ms-powerpoint, */* Accept-Language: de,de,de Referer: http://reinform.hn.org/squirrel/src/compose.php,http://reinform.hn.org/squirrel/src/compose.php,http://reinform.hn.org/squirrel/src/compose.php Pragma: no-cache Cookie: squirrelmail_language=de_DE; key=AW0RUMJgLK4%3D; PHPSESSID=0afb8733761a1723a006ce1676d9aa7b Accept-Encoding: gzip, deflate,gzip, deflate,gzip, deflate -----------------------------7d29f1d3bad02b2 Content-Disposition: form-data; name="session" 7 -----------------------------7d29f1d3bad02b2 Content-Disposition: form-data; name="send_to" -----------------------------7d29f1d3bad02b2 The wrong part is the Content-Type which contains more than a single boundary statement (which is a rfc2616 violation, because the parameters are not seperated by ","). PHP takes everything after the first '=' as the boundary and will therefore look for a boundary "---------------------------7d29f1d3bad02b2,multipart/form-data; boundary=---------------------------7d29f1d3bad02b2,multipart/form-data; boundary=---------------------------7d29f1d3bad02b2" which is never found in the data stream. Therefore no parts are found and no variables are declared. The following (trivial) patch will fix the bug and is based upong the current CVS version of PHP-4.2.2: diff -r -u php-4.2.2-orig/main/rfc1867.c php-4.2.2/main/rfc1867.c --- php-4.2.2-orig/main/rfc1867.c Sat Jul 20 21:17:52 2002 +++ php-4.2.2/main/rfc1867.c Wed Aug 7 20:26:28 2002 @@ -599,7 +599,7 @@ SAPI_API SAPI_POST_HANDLER_FUNC(rfc1867_post_handler) { - char *boundary, *s=NULL, *start_arr=NULL, *array_index=NULL; + char *boundary, *boundary_end, *s=NULL, *start_arr=NULL, *array_index=NULL; char *temp_filename=NULL, *lbuf=NULL, *abuf=NULL; int boundary_len=0, total_bytes=0, cancel_upload=0, is_arr_upload=0, array_len=0, max_file_size=0; zval *http_post_files=NULL; @@ -620,6 +620,10 @@ sapi_module.sapi_error(E_WARNING, "Missing boundary in multipart/form-data POST data"); return; } + /* search for the end of the boundary */ + boundary_end = strchr(boundary, ','); + if ( boundary_end ) *boundary_end = 0; + boundary++; boundary_len = strlen(boundary); Would you please apply the patch? Thanks, Till +-------+-------------------------------------------------------------+ | | dr. tilmann bubeck reinform medien- und | | rein | informationstechnologie AG | | form | cell.: +49 (172) 8 84 29 72 koenigstrasse 80 | | AG | fax : +49 (711) 7 22 77 34 70173 stuttgart / germany | | | email: t.bubeck@reinform.de http://www.reinform.de | +-------+-------------------------------------------------------------+ ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=18792&edit=1

« previous php.bugs (#16200) next »