Edit report at https://bugs.php.net/bug.php?id=72501&edit=1
ID: 72501
Updated by: stas@php.net
Reported by: loianhtuan at gmail dot com
Summary: create_function can execute code
-Status: Open
+Status: Not a bug
-Type: Security
+Type: Bug
Package: Unknown/Other Function
PHP Version: 7.1Git-2016-06-27 (Git)
Block user comment: N
Private report: Y
New Comment:
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
If you allow user-specified data into the body of your created functions, you should filter that
data. Also, create_function is not recommended for use in any current version of PHP, see http://php.net/create_function
Previous Comments:
------------------------------------------------------------------------
[2016-06-27 10:16:54] loianhtuan at gmail dot com
Description:
------------
create_function puts the given arguments to the "function" block then eval, so attacker
can use a close bracket to escape this block and execute the code without calling the new function.
Test script:
---------------
<?php
$a = create_function('$b','}echo "this should not be executed\n";{');
?>
Expected result:
----------------
vps@pc:~ /opt/php7/bin/php a.php
vps@pc:~
Actual result:
--------------
vps@pc:~ /opt/php7/bin/php -v
PHP 7.1.0-dev (cli) (built: Jun 27 2016 11:16:33) ( NTS DEBUG )
Copyright (c) 1997-2016 The PHP Group
Zend Engine v3.1.0-dev, Copyright (c) 1998-2016 Zend Technologies
vps@pc:~ /opt/php7/bin/php a.php
this should not be executed
vps@pc:~
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72501&edit=1