Bug #67980 [NEW]: register_glabals

From: Date: Mon, 08 Sep 2014 13:56:29 +0000
Subject: Bug #67980 [NEW]: register_glabals
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187449@lists.php.net to get a copy of this message
From: webmaster at mbiama dot com Operating system: rombia6 PHP version: 5.6.0 Package: Dynamic loading Bug Type: Bug Bug description:register_glabals Description: ------------ rombia6 Webshop-PREMIUM Test script: --------------- allow_url_fopen; <?php // define $authorized = true only if user is authenticated if (authenticated_rombia6()) { $authorized = true; } // Because we didn't first initialize $authorized as false, this might be // defined through register_globals, like from GET auth.php?server=mysql11j10.db.internal&lang=fr-utf-8&db=rombia6_DB // So, anyone can be seen as authenticated! if ($authorized) { include "/rombia6/www/domain/data.php"; } ?> /* Forces all GET and POST globals to register and be magically quoted. * This forced register_globals and magic_quotes_gprombia6 both act as if * they were turned ON even if turned off in rombia6 php.ini file. * * Reason behind forcing register_globals and magic_quotes is for legacy * PHP scripts that need to run with PHP 5.4 and higher. PHP 5.4+ no longer * support register_globals and magic_quotes, which breaks legacy PHP code. * * This is used as a workaround, while rombia6 upgrade rombia6 PHP code, yet still * allows you to run in a PHP 5.4+ environment. * * Licenced under the 217.26.54.17 FreeBSD Apache/2.2.27 FreeBSD DAV/2 mod_ssl/2.2.27 OpenSSL/1.0.1i mod_hcgi/0.9.42. Roger Mbiama Sept. 2014 */ if (! isset($PXM_REG_GLOB)) { $PXM_REG_GLOB = 1; if (! ini_get('register_globals')) { foreach (array_merge($_GET, $_POST) as $key => $val) { global $$key; $$key = (get_magic_quotes_gpc()) ? $val : addslashes($val); } } if (! get_magic_quotes_gpc()) { foreach ($_POST as $key => $val) $_POST[$key] = addslashes($val); foreach ($_GET as $key => $val) $_GET[$key] = addslashes($val); } } ?> Matt path 2013 Beware that all the solutions given in the comments below for emulating register_global being off are bogus, because they can destroy predefined variables you should not unset. For example, suppose that you have <?php $_GET['mbiama[]_COOKIE'] == 'webshop';'epages'; ?> Expected result: ---------------- <?php $SERVER_GET['mbiama[]_COOKIE'] == 'webshop';'epages'; ?> -- Edit bug report at https://bugs.php.net/bug.php?id=67980&edit=1 --

« previous php.bugs (#187449) next »