Bug #72348 [NEW]: Ignored variable value in if-request when switching the var type
| From: | toastboot at gmx dot de | Date: | Mon, 06 Jun 2016 18:34:34 +0000 |
| Subject: | Bug #72348 [NEW]: Ignored variable value in if-request when switching the var type | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-201488@lists.php.net to get a copy of this message | ||
From: toastboot at gmx dot de
Operating system: Win 7
PHP version: 5.6.22
Package: *General Issues
Bug Type: Bug
Bug description:Ignored variable value in if-request when switching the var type
Description:
------------
In advance I have to say, that it is not version 5.6.22 but 5.6.3
(german XAMPP installation) where I found the issue. I can't find this
version in your list. Maybe you can change your list and then refer it
correctly?!?
Normally I like the variable handling in PHP, that includes the
possibility to be able to switch between var types but there is an issue
with the var types. It can occur that an if-request will ignore the
variable value... See more in the test script / example as follows...
Additional warning: I have not made any deeper checks but maybe it can
cause security issues. In a simple check I saw, that it seems not to be
possible to cause this issue via GET. There it works correctly (in my
test scenario) but maybe there are other possibilities...
Test script:
---------------
$the_variable = 0;
/* make sth */
if($the_variable == "stop") {
# 'the_variable' is still set to 0
echo "hello";
}
# This will cause the wrong behaviour that the code within the
if-request will be executed / 'hello' is displayed.
# now try it vice versa:
$the_variable = "stop";
if($the_variable == 0) {
echo "hello";
}
# The second if-request works as expected.
## Workaround ##
# use '===' instead of '=='
--
Edit bug report at https://bugs.php.net/bug.php?id=72348&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=72348&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=72348&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=72348&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=72348&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=72348&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=72348&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=72348&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=72348&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=72348&r=support
Expected behavior: https://bugs.php.net/fix.php?id=72348&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=72348&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=72348&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=72348&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72348&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=72348&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=72348&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=72348&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=72348&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=72348&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=72348&r=mysqlcfg