Bug #69948 [PATCH]: path/domain are not sanitized for special characters in setcookie
| From: | cmb@php.net | Date: | Sun, 28 Jun 2015 11:49:30 +0000 |
| Subject: | Bug #69948 [PATCH]: path/domain are not sanitized for special characters in setcookie | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-193957@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69948&edit=1
ID: 69948
Patch added by: cmb@php.net
Reported by: neal at fb dot com
Summary: path/domain are not sanitized for special characters
in setcookie
Status: Open
Type: Bug
Package: HTTP related
Operating System: N/A
PHP Version: 5.6.10
Block user comment: N
Private report: N
New Comment:
The following patch has been added/updated:
Patch Name: 0001-Fix-69948
Revision: 1435492169
URL: https://bugs.php.net/patch-display.php?bug=69948&patch=0001-Fix-69948&revision=1435492169
Previous Comments:
------------------------------------------------------------------------
[2015-06-26 23:09:44] neal at fb dot com
Description:
------------
In the highly unlikely event where path or domain are user-controlled, it is possible to inject
semi-colons, equals signs, etc into a value. This allows you to provide arbitrary additional
key/value pairs inside of a Set-Cookie header (ie: set an expires header 20 years from now, add the
HttpOnly flag, etc).
There is already sanitization in the code for checking the "value" parameter: the same
logic should be applied to domain and path.
Test script:
---------------
<?php
setcookie('foo', 'bar', 0, $_GET['path'], $_GET['domain']);
Expected result:
----------------
Making a request with path=asdf;asdf&domain=foobar;%20secure results in no cookie being sent
(identical to how it's currently handled when the value has invalid characters).
Actual result:
--------------
Header looks like Set-Cookie: foo=bar; path=asdf;asdf; domain=foobar; secure
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69948&edit=1