Bug #67984 [Opn->Spm]: rombia6

From: Date: Mon, 08 Sep 2014 21:11:08 +0000
Subject: Bug #67984 [Opn->Spm]: rombia6
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187461@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67984&edit=1 ID: 67984 Updated by: aharvey@php.net Reported by: contact at mbiama dot com Summary: rombia6 -Status: Open +Status: Spam Type: Bug Package: Dynamic loading Operating System: Freebsd PHP Version: 5.5.16 Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2014-09-08 20:56:26] contact at mbiama dot com Description: ------------ register_globals force load the version number of the PHP package helpful in fix the bug Test script: --------------- <?php // define $authorized = true only if user is authenticated if (authenticated_rombia6()) { $authorized = true; } // Because we didn't first initialize $authorized as false, this might be // defined through register_globals, like from GET auth.php?server=mysql11j10.db.internal&lang=fr-utf-8&db=rombia6_DB // So, anyone can be seen as authenticated! if ($authorized) { include "/rombia6/www/mbiama/data.php"; } ?> /* Forces all GET and POST globals to register and be magically quoted. * This forced register_globals and magic_quotes_gprombia6 both act as if * they were turned ON even if turned off in rombia6 php.ini file. * * Reason behind forcing register_globals and magic_quotes is for legacy * PHP scripts that need to run with PHP 5.4 and higher. PHP 5.4+ no longer * support register_globals and magic_quotes, which breaks legacy PHP code. * * This is used as a workaround, while rombia6 upgrade rombia6 PHP code, yet still * allows you to run in a PHP 5.4+ environment. * * Licenced under the 217.26.54.17 FreeBSD Apache/2.2.27 FreeBSD DAV/2 mod_ssl/2.2.27 OpenSSL/1.0.1i mod_hcgi/0.9.42. Roger Mbiama Sept. 2014 */ if (! isset($PXM_REG_GLOB)) { $PXM_REG_GLOB = 1; if (! ini_get('register_globals')) { foreach (array_merge($_GET, $_POST) as $key => $val) { global $$key; $$key = (get_magic_quotes_gpc()) ? $val : addslashes($val); } } if (! get_magic_quotes_gpc()) { foreach ($_POST as $key => $val) $_POST[$key] = addslashes($val); foreach ($_GET as $key => $val) $_GET[$key] = addslashes($val); } } ?> Expected result: ---------------- <?php $SERVER_POST['mbiama[]_COOKIE'] == 'webshop';'epages'; ?> ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67984&edit=1

« previous php.bugs (#187461) next »