#19286 [NEW]: header() Control Char Injection
| From: | mattmurphy at kc dot rr dot com | Date: | Sat, 07 Sep 2002 21:14:22 +0000 |
| Subject: | #19286 [NEW]: header() Control Char Injection | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-18640@lists.php.net to get a copy of this message | ||
From: mattmurphy@kc.rr.com
Operating system: Win32
PHP version: 4.2.3
PHP Bug Type: Output Control
Bug description: header() Control Char Injection
I made a quite primitive use of the header() function in a redirect
script:
<?php
if (isset($_GET["url"])) {
header("Location: " . $_GET["url"]);
}
?>
But, no imagine for a second:
url=http%3A%2F%2Fwww.yahoo.com%2F%0D%0A%0D%0A%3Cscript%3Ealert%28document.cookie%29%3B%3C%2FSCRIPT%3E%0D%0A%0D%0A
Which causes:
Location: http://www.yahoo.com/
<script>alert(document.cookie)</script>
Another interesting thing about this is that it (possibly) allows
bypassing output buffering(?).
If nothing else, this is a documentation problem, as the header() docs say
that it will modify a single header, but it also allows body content to be
manipulated.
--
Edit bug report at http://bugs.php.net/?id=19286&edit=1
--
Try a CVS snapshot: http://bugs.php.net/fix.php?id=19286&r=trysnapshot
Fixed in CVS: http://bugs.php.net/fix.php?id=19286&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=19286&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=19286&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=19286&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=19286&r=support
Expected behavior: http://bugs.php.net/fix.php?id=19286&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=19286&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=19286&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=19286&r=globals