#19286 [WFx->]: header() Control Char Injection

From: Date: Sun, 08 Sep 2002 11:47:15 +0000
Subject: #19286 [WFx->]: header() Control Char Injection
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-18661@lists.php.net to get a copy of this message
ID: 19286 Updated by: sesser@php.net Reported By: mattmurphy@kc.rr.com Status: Won't fix Bug Type: Output Control Operating System: Win32 PHP Version: 4.2.3 New Comment: BTW: Your little example does exactly nothing... All Browsers I use (IE, Mozilla, Opera) ignore the body if they find a Location header. The only possible "danger" is Cookie injection. Previous Comments: ------------------------------------------------------------------------ [2002-09-07 21:46:31] yohgaki@php.net Document mentions variables must be checked before passing it to header() already. header() should be able to send multiple line header also. ------------------------------------------------------------------------ [2002-09-07 21:44:09] sniper@php.net Have you ever thought of shooting yourself? You can also pass user input to fopen()..or exect() (that's really for the brave ones to try..) ------------------------------------------------------------------------ [2002-09-07 16:14:22] mattmurphy@kc.rr.com I made a quite primitive use of the header() function in a redirect script: <?php if (isset($_GET["url"])) { header("Location: " . $_GET["url"]); } ?> But, no imagine for a second: url=http%3A%2F%2Fwww.yahoo.com%2F%0D%0A%0D%0A%3Cscript%3Ealert%28document.cookie%29%3B%3C%2FSCRIPT%3E%0D%0A%0D%0A Which causes: Location: http://www.yahoo.com/ <script>alert(document.cookie)</script> Another interesting thing about this is that it (possibly) allows bypassing output buffering(?). If nothing else, this is a documentation problem, as the header() docs say that it will modify a single header, but it also allows body content to be manipulated. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=19286&edit=1

« previous php.bugs (#18661) next »