Bug #24 [Com]: PHO allowing the overwriting of environment variables

From: Date: Mon, 29 Aug 2011 08:22:41 +0000
Subject: Bug #24 [Com]: PHO allowing the overwriting of environment variables
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-163058@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=24&edit=1 ID: 24 Comment by: junxing dot lin at yahoo dot com Reported by: alden at math dot ohio-state dot edu Summary: PHO allowing the overwriting of environment variables Status: Closed Type: Bug Package: Other Operating System: Solaris 2.6 PHP Version: 3.0 Latest CVS Block user comment: N Private report: N New Comment: http://www.chishairstraighteners.net chi flat iron http://www.chishairstraighteners.net chi flat irons http://www.chishairstraighteners.net chi hair straightener http://www.chishairstraighteners.net chi hair straighteners Previous Comments: ------------------------------------------------------------------------ [1998-01-30 20:54:55] zeev Fixed. Environment variables will now overwrite any GET/POST/Cookie variable. ------------------------------------------------------------------------ [1998-01-30 13:39:57] alden at math dot ohio-state dot edu Hi, According to the php 2.0 doc's (I am using 3.0) PHP isn't supposed to allow the overwriting of environment variables by adding "?REMOTE_HOST=some.bogus.host". I have the following file "test.php3" in my doc root: <html><head><title>test</title></head><body> <?echo "remote_host=$REMOTE_HOST";?> </body></html> And then I pointed netscape at: http://my.machine.edu/test.php3?REMOTE_HOST=some.bogus.host And it returned: remote_host=some.bogus.host Am I missing something? On a similar topic, I need to get at the REMOTE_USER environment variable without the user being able to change this. I use the .htaccess method of authentication, but I need to know the username of the remote user. In my old perl scripts I just checked REMOTE_USER, but PHP seems to allow the user to overwrite this. ...thnx, ...dave alden ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=24&edit=1

« previous php.bugs (#163058) next »