#19286 [Opn->Bgs]: header() Control Char Injection
| From: | sniper@php.net | Date: | Sun, 08 Sep 2002 02:44:09 +0000 |
| Subject: | #19286 [Opn->Bgs]: header() Control Char Injection | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-18652@lists.php.net to get a copy of this message | ||
ID: 19286
Updated by: sniper@php.net
Reported By: mattmurphy@kc.rr.com
-Status: Open
+Status: Bogus
Bug Type: Output Control
Operating System: Win32
PHP Version: 4.2.3
New Comment:
Have you ever thought of shooting yourself?
You can also pass user input to fopen()..or exect() (that's really for
the brave ones to try..)
Previous Comments:
------------------------------------------------------------------------
[2002-09-07 16:14:22] mattmurphy@kc.rr.com
I made a quite primitive use of the header() function in a redirect
script:
<?php
if (isset($_GET["url"])) {
header("Location: " . $_GET["url"]);
}
?>
But, no imagine for a second:
url=http%3A%2F%2Fwww.yahoo.com%2F%0D%0A%0D%0A%3Cscript%3Ealert%28document.cookie%29%3B%3C%2FSCRIPT%3E%0D%0A%0D%0A
Which causes:
Location: http://www.yahoo.com/
<script>alert(document.cookie)</script>
Another interesting thing about this is that it (possibly) allows
bypassing output buffering(?).
If nothing else, this is a documentation problem, as the header() docs
say that it will modify a single header, but it also allows body
content to be manipulated.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=19286&edit=1