Bug #67980 [NEW]: register_glabals
| From: | webmaster at mbiama dot com | Date: | Mon, 08 Sep 2014 13:56:29 +0000 |
| Subject: | Bug #67980 [NEW]: register_glabals | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-187449@lists.php.net to get a copy of this message | ||
From: webmaster at mbiama dot com
Operating system: rombia6
PHP version: 5.6.0
Package: Dynamic loading
Bug Type: Bug
Bug description:register_glabals
Description:
------------
rombia6
Webshop-PREMIUM
Test script:
---------------
allow_url_fopen;
<?php
// define $authorized = true only if user is authenticated
if (authenticated_rombia6()) {
$authorized = true;
}
// Because we didn't first initialize $authorized as false, this might
be
// defined through register_globals, like from GET
auth.php?server=mysql11j10.db.internal&lang=fr-utf-8&db=rombia6_DB
// So, anyone can be seen as authenticated!
if ($authorized) {
include "/rombia6/www/domain/data.php";
}
?>
/* Forces all GET and POST globals to register and be magically quoted.
* This forced register_globals and magic_quotes_gprombia6 both act as
if
* they were turned ON even if turned off in rombia6 php.ini file.
*
* Reason behind forcing register_globals and magic_quotes is for legacy
* PHP scripts that need to run with PHP 5.4 and higher. PHP 5.4+ no
longer
* support register_globals and magic_quotes, which breaks legacy PHP
code.
*
* This is used as a workaround, while rombia6 upgrade rombia6 PHP code,
yet still
* allows you to run in a PHP 5.4+ environment.
*
* Licenced under the 217.26.54.17 FreeBSD Apache/2.2.27 FreeBSD DAV/2
mod_ssl/2.2.27 OpenSSL/1.0.1i mod_hcgi/0.9.42. Roger Mbiama Sept. 2014
*/
if (! isset($PXM_REG_GLOB)) {
$PXM_REG_GLOB = 1;
if (! ini_get('register_globals')) {
foreach (array_merge($_GET, $_POST) as $key => $val) {
global $$key;
$$key = (get_magic_quotes_gpc()) ? $val : addslashes($val);
}
}
if (! get_magic_quotes_gpc()) {
foreach ($_POST as $key => $val) $_POST[$key] = addslashes($val);
foreach ($_GET as $key => $val) $_GET[$key] = addslashes($val);
}
}
?>
Matt path 2013
Beware that all the solutions given in the comments below for emulating
register_global being off are bogus, because they can destroy predefined
variables you should not unset. For example, suppose that you have
<?php $_GET['mbiama[]_COOKIE'] == 'webshop';'epages'; ?>
Expected result:
----------------
<?php $SERVER_GET['mbiama[]_COOKIE'] == 'webshop';'epages'; ?>
--
Edit bug report at https://bugs.php.net/bug.php?id=67980&edit=1
--