Bug #69948 [PATCH]: path/domain are not sanitized for special characters in setcookie

From: Date: Sun, 28 Jun 2015 11:49:30 +0000
Subject: Bug #69948 [PATCH]: path/domain are not sanitized for special characters in setcookie
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193957@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69948&edit=1 ID: 69948 Patch added by: cmb@php.net Reported by: neal at fb dot com Summary: path/domain are not sanitized for special characters in setcookie Status: Open Type: Bug Package: HTTP related Operating System: N/A PHP Version: 5.6.10 Block user comment: N Private report: N New Comment: The following patch has been added/updated: Patch Name: 0001-Fix-69948 Revision: 1435492169 URL: https://bugs.php.net/patch-display.php?bug=69948&patch=0001-Fix-69948&revision=1435492169 Previous Comments: ------------------------------------------------------------------------ [2015-06-26 23:09:44] neal at fb dot com Description: ------------ In the highly unlikely event where path or domain are user-controlled, it is possible to inject semi-colons, equals signs, etc into a value. This allows you to provide arbitrary additional key/value pairs inside of a Set-Cookie header (ie: set an expires header 20 years from now, add the HttpOnly flag, etc). There is already sanitization in the code for checking the "value" parameter: the same logic should be applied to domain and path. Test script: --------------- <?php setcookie('foo', 'bar', 0, $_GET['path'], $_GET['domain']); Expected result: ---------------- Making a request with path=asdf;asdf&domain=foobar;%20secure results in no cookie being sent (identical to how it's currently handled when the value has invalid characters). Actual result: -------------- Header looks like Set-Cookie: foo=bar; path=asdf;asdf; domain=foobar; secure ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=69948&edit=1

« previous php.bugs (#193957) next »