Bug #48597 [Opn]: Unclosed array keys break space escaping in $_GET/POST/REQUEST
| From: | cmb@php.net | Date: | Wed, 29 Jul 2015 20:12:09 +0000 |
| Subject: | Bug #48597 [Opn]: Unclosed array keys break space escaping in $_GET/POST/REQUEST | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-194824@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=48597&edit=1
ID: 48597
Updated by: cmb@php.net
Reported by: crmalibu at gmail dot com
Summary: Unclosed array keys break space escaping in
$_GET/POST/REQUEST
Status: Open
Type: Bug
Package: *General Issues
Operating System: *
PHP Version: 5.*, 6CVS (2009-07-01)
Block user comment: N
Private report: N
New Comment:
IMO this is not a bug (at least I won't fix it). The mangling of
some special characters may have made sense when variables were
automatically created from GPC parameters (register_globals), but
nowadays I'd rather get rid of the mangling at all.
Previous Comments:
------------------------------------------------------------------------
[2013-12-05 19:41:47] mike@php.net
Related To: Bug #50314
------------------------------------------------------------------------
[2009-10-23 21:28:13] e dot ehritt at web dot de
I left a report too. http://bugs.php.net/bug.php?id=49975
If I follow the documentation, a key of an array is a string. That means, a key "abc[des]"
is possible. (e. g. $a=array("abc[des]"=>'d'); )
<form action="s.php" method="post">
<input name="a[b[c]]" type="text"/>
<input type="submit">
</form>
$_POST=array('a'=>array('b[c]'=>'d'));
Both should result in even structure, but it does not. There are no reason, why incoming datas could
not follow the same rules as data in a script.
------------------------------------------------------------------------
[2009-10-14 02:42:39] chrisstocktonaz at gmail dot com
Sorry for extra noise.. it seems my patch mixed the case of something like: <input
name="badvar[[[. [ . . .]>
So updated:
Index: main/php_variables.c
===================================================================
--- main/php_variables.c (revision 289602)
+++ main/php_variables.c (working copy)
@@ -61,6 +61,7 @@
{
char *p = NULL;
char *ip; /* index pointer */
+ char *pmarker;
char *index, *escaped_index = NULL;
char *var, *var_orig;
int var_len, index_len;
@@ -100,12 +101,18 @@
if (*p == ' ' || *p == '.') {
*p='_';
} else if (*p == '[') {
- is_array = 1;
- ip = p;
- *p = 0;
- break;
+ for(pmarker = p; *pmarker; pmarker++) {
+ if(*pmarker == ']') {
+ is_array = 1;
+ ip = p;
+ *p = 0;
+ goto var_continue;
+ }
+ }
+ *p='_';
}
}
+ var_continue:
var_len = p - var;
if (var_len==0) { /* empty variable name, or variable name with a space in it */
@@ -225,6 +232,13 @@
} else {
escaped_index = index;
}
+ /* clean up the array index */
+ for (pmarker = escaped_index; *pmarker; pmarker++) {
+ if (*pmarker == '[' || *pmarker == ']'
+ || *pmarker == '.' || isspace(*pmarker)) {
+ *pmarker = '_';
+ }
+ }
/*
* According to rfc2965, more specific paths are listed above the less specific ones.
* If we encounter a duplicate cookie name, we should skip it, since it is not possible
------------------------------------------------------------------------
[2009-10-13 22:36:47] chrisstocktonaz at gmail dot com
Here is a fix.
Index: main/php_variables.c
===================================================================
--- main/php_variables.c (revision 289602)
+++ main/php_variables.c (working copy)
@@ -61,6 +61,7 @@
{
char *p = NULL;
char *ip; /* index pointer */
+ char *pmarker; /* marker to index before */
char *index, *escaped_index = NULL;
char *var, *var_orig;
int var_len, index_len;
@@ -100,12 +101,19 @@
if (*p == ' ' || *p == '.') {
*p='_';
} else if (*p == '[') {
- is_array = 1;
- ip = p;
- *p = 0;
- break;
+ for(pmarker = p; *pmarker; pmarker++) {
+ if(*pmarker == ']') {
+ is_array = 1;
+ ip = p;
+ *p = 0;
+ goto var_continue;
+ }
+ }
+ *p='_';
}
}
+
+ var_continue:
var_len = p - var;
if (var_len==0) { /* empty variable name, or variable name with a space in it */
------------------------------------------------------------------------
[2009-09-27 02:52:19] jani@php.net
See also bug #49683
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=48597
--
Edit this bug report at https://bugs.php.net/bug.php?id=48597&edit=1