Bug #48597 [Opn]: Unclosed array keys break space escaping in $_GET/POST/REQUEST

From: Date: Wed, 29 Jul 2015 20:12:09 +0000
Subject: Bug #48597 [Opn]: Unclosed array keys break space escaping in $_GET/POST/REQUEST
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194824@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=48597&edit=1 ID: 48597 Updated by: cmb@php.net Reported by: crmalibu at gmail dot com Summary: Unclosed array keys break space escaping in $_GET/POST/REQUEST Status: Open Type: Bug Package: *General Issues Operating System: * PHP Version: 5.*, 6CVS (2009-07-01) Block user comment: N Private report: N New Comment: IMO this is not a bug (at least I won't fix it). The mangling of some special characters may have made sense when variables were automatically created from GPC parameters (register_globals), but nowadays I'd rather get rid of the mangling at all. Previous Comments: ------------------------------------------------------------------------ [2013-12-05 19:41:47] mike@php.net Related To: Bug #50314 ------------------------------------------------------------------------ [2009-10-23 21:28:13] e dot ehritt at web dot de I left a report too. http://bugs.php.net/bug.php?id=49975 If I follow the documentation, a key of an array is a string. That means, a key "abc[des]" is possible. (e. g. $a=array("abc[des]"=>'d'); ) <form action="s.php" method="post"> <input name="a[b[c]]" type="text"/> <input type="submit"> </form> $_POST=array('a'=>array('b[c]'=>'d')); Both should result in even structure, but it does not. There are no reason, why incoming datas could not follow the same rules as data in a script. ------------------------------------------------------------------------ [2009-10-14 02:42:39] chrisstocktonaz at gmail dot com Sorry for extra noise.. it seems my patch mixed the case of something like: <input name="badvar[[[. [ . . .]> So updated: Index: main/php_variables.c =================================================================== --- main/php_variables.c (revision 289602) +++ main/php_variables.c (working copy) @@ -61,6 +61,7 @@ { char *p = NULL; char *ip; /* index pointer */ + char *pmarker; char *index, *escaped_index = NULL; char *var, *var_orig; int var_len, index_len; @@ -100,12 +101,18 @@ if (*p == ' ' || *p == '.') { *p='_'; } else if (*p == '[') { - is_array = 1; - ip = p; - *p = 0; - break; + for(pmarker = p; *pmarker; pmarker++) { + if(*pmarker == ']') { + is_array = 1; + ip = p; + *p = 0; + goto var_continue; + } + } + *p='_'; } } + var_continue: var_len = p - var; if (var_len==0) { /* empty variable name, or variable name with a space in it */ @@ -225,6 +232,13 @@ } else { escaped_index = index; } + /* clean up the array index */ + for (pmarker = escaped_index; *pmarker; pmarker++) { + if (*pmarker == '[' || *pmarker == ']' + || *pmarker == '.' || isspace(*pmarker)) { + *pmarker = '_'; + } + } /* * According to rfc2965, more specific paths are listed above the less specific ones. * If we encounter a duplicate cookie name, we should skip it, since it is not possible ------------------------------------------------------------------------ [2009-10-13 22:36:47] chrisstocktonaz at gmail dot com Here is a fix. Index: main/php_variables.c =================================================================== --- main/php_variables.c (revision 289602) +++ main/php_variables.c (working copy) @@ -61,6 +61,7 @@ { char *p = NULL; char *ip; /* index pointer */ + char *pmarker; /* marker to index before */ char *index, *escaped_index = NULL; char *var, *var_orig; int var_len, index_len; @@ -100,12 +101,19 @@ if (*p == ' ' || *p == '.') { *p='_'; } else if (*p == '[') { - is_array = 1; - ip = p; - *p = 0; - break; + for(pmarker = p; *pmarker; pmarker++) { + if(*pmarker == ']') { + is_array = 1; + ip = p; + *p = 0; + goto var_continue; + } + } + *p='_'; } } + + var_continue: var_len = p - var; if (var_len==0) { /* empty variable name, or variable name with a space in it */ ------------------------------------------------------------------------ [2009-09-27 02:52:19] jani@php.net See also bug #49683 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=48597 -- Edit this bug report at https://bugs.php.net/bug.php?id=48597&edit=1

« previous php.bugs (#194824) next »