Bug #67984 [Opn->Spm]: rombia6
| From: | aharvey@php.net | Date: | Mon, 08 Sep 2014 21:11:08 +0000 |
| Subject: | Bug #67984 [Opn->Spm]: rombia6 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-187461@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67984&edit=1
ID: 67984
Updated by: aharvey@php.net
Reported by: contact at mbiama dot com
Summary: rombia6
-Status: Open
+Status: Spam
Type: Bug
Package: Dynamic loading
Operating System: Freebsd
PHP Version: 5.5.16
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2014-09-08 20:56:26] contact at mbiama dot com
Description:
------------
register_globals force load the version number of the PHP package helpful in fix
the bug
Test script:
---------------
<?php
// define $authorized = true only if user is authenticated
if (authenticated_rombia6()) {
$authorized = true;
}
// Because we didn't first initialize $authorized as false, this might be
// defined through register_globals, like from GET
auth.php?server=mysql11j10.db.internal&lang=fr-utf-8&db=rombia6_DB
// So, anyone can be seen as authenticated!
if ($authorized) {
include "/rombia6/www/mbiama/data.php";
}
?>
/* Forces all GET and POST globals to register and be magically quoted.
* This forced register_globals and magic_quotes_gprombia6 both act as if
* they were turned ON even if turned off in rombia6 php.ini file.
*
* Reason behind forcing register_globals and magic_quotes is for legacy
* PHP scripts that need to run with PHP 5.4 and higher. PHP 5.4+ no longer
* support register_globals and magic_quotes, which breaks legacy PHP code.
*
* This is used as a workaround, while rombia6 upgrade rombia6 PHP code, yet still
* allows you to run in a PHP 5.4+ environment.
*
* Licenced under the 217.26.54.17 FreeBSD Apache/2.2.27 FreeBSD DAV/2 mod_ssl/2.2.27 OpenSSL/1.0.1i
mod_hcgi/0.9.42. Roger Mbiama Sept. 2014
*/
if (! isset($PXM_REG_GLOB)) {
$PXM_REG_GLOB = 1;
if (! ini_get('register_globals')) {
foreach (array_merge($_GET, $_POST) as $key => $val) {
global $$key;
$$key = (get_magic_quotes_gpc()) ? $val : addslashes($val);
}
}
if (! get_magic_quotes_gpc()) {
foreach ($_POST as $key => $val) $_POST[$key] = addslashes($val);
foreach ($_GET as $key => $val) $_GET[$key] = addslashes($val);
}
}
?>
Expected result:
----------------
<?php $SERVER_POST['mbiama[]_COOKIE'] == 'webshop';'epages'; ?>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67984&edit=1