Bug #64582 [Opn]: file_get_contents() handles redirects wrong
Edit report at https://bugs.php.net/bug.php?id=64582&edit=1
ID: 64582
Updated by: cmb@php.net
Reported by: spam2 at rhsoft dot net
Summary: file_get_contents() handles redirects wrong
Status: Open
Type: Bug
-Package: Scripting Engine problem
+Package: Streams related
Operating System: Linux
PHP Version: 5.4.13
Block user comment: N
Private report: N
New Comment:
RFC 7231 which obsoletes RFC 2616 allows relative references[1],
though. It seems to me that the http:// stream wrappers should
comply.
[1] <http://tools.ietf.org/html/rfc7231#section-7.1.2>
Previous Comments:
------------------------------------------------------------------------
[2013-04-04 15:57:09] spam2 at rhsoft dot net
i know that, but it is not that easy to generate everytime a full qualified URL and since any other
http-client translates the ../ PHP should act the same way
------------------------------------------------------------------------
[2013-04-04 15:53:58] johannes@php.net
RFC 2616 Section 14.30 requires "a single absolute URI." for the location header. Any
relative location is not standards compliant.
------------------------------------------------------------------------
[2013-04-04 14:55:58] spam2 at rhsoft dot net
Description:
------------
[line "182"] [id "950103"] [msg "path traversal attack"] [data
"../"] [hostname "test.test.rh"] [uri
"/contentlounge/updateservice/cms_demo/cms//../cms.php"] [unique_id
"UV2MrQoAAGMAAE356XkAAAAF"]
in the folder /cms is a simple index.php with header('Location: ../cms.php');
every normal browser translates path and does not trigger modsec
php triggers the "path traversal"-rule
Expected result:
----------------
call the URL /contentlounge/updateservice/cms_demo/cms/cms.php
Actual result:
--------------
calling the URL /contentlounge/updateservice/cms_demo/cms//../cms.php
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=64582&edit=1
Thread (5 messages)