#19286 [NEW]: header() Control Char Injection

From: Date: Sat, 07 Sep 2002 21:14:22 +0000
Subject: #19286 [NEW]: header() Control Char Injection
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-18640@lists.php.net to get a copy of this message
From: mattmurphy@kc.rr.com Operating system: Win32 PHP version: 4.2.3 PHP Bug Type: Output Control Bug description: header() Control Char Injection I made a quite primitive use of the header() function in a redirect script: <?php if (isset($_GET["url"])) { header("Location: " . $_GET["url"]); } ?> But, no imagine for a second: url=http%3A%2F%2Fwww.yahoo.com%2F%0D%0A%0D%0A%3Cscript%3Ealert%28document.cookie%29%3B%3C%2FSCRIPT%3E%0D%0A%0D%0A Which causes: Location: http://www.yahoo.com/ <script>alert(document.cookie)</script> Another interesting thing about this is that it (possibly) allows bypassing output buffering(?). If nothing else, this is a documentation problem, as the header() docs say that it will modify a single header, but it also allows body content to be manipulated. -- Edit bug report at http://bugs.php.net/?id=19286&edit=1 -- Try a CVS snapshot: http://bugs.php.net/fix.php?id=19286&r=trysnapshot Fixed in CVS: http://bugs.php.net/fix.php?id=19286&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=19286&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=19286&r=needtrace Try newer version: http://bugs.php.net/fix.php?id=19286&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=19286&r=support Expected behavior: http://bugs.php.net/fix.php?id=19286&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=19286&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=19286&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=19286&r=globals

« previous php.bugs (#18640) next »