Bug #73354 [Ver]: URL filter validator broken
Edit report at https://bugs.php.net/bug.php?id=73354&edit=1
ID: 73354
Updated by: cmb@php.net
Reported by: mehulmpt at gmail dot com
Summary: URL filter validator broken
Status: Verified
Type: Bug
Package: Filter related
Operating System: All
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
Indeed, there is an issue in php_filter_url()[1], namely that
PUNCTUATION and NATIONAL are not allowed in URLs according to RFC
1738. While these are listed in the BNF, they are never used.
However, according to the documentation FILTER_VALIDATE_URL
conforms to RFC 2396, which differs from RFC 1738.
[1] <http://lxr.php.net/source/xref/PHP-MASTER/ext/filter/sanitizing_filters.c#php_filter_url>
Previous Comments:
------------------------------------------------------------------------
[2016-10-19 20:07:15] mehulmpt at gmail dot com
Description:
------------
filter validate URL is broken for non HTTP(s) protocols as it allows a variety of URLs to pass
through though they are not valid URLs (possible XSS attacks if URL is displayed after validating)
Test script:
---------------
<?php
echo filter_var("ftp://oscarotero.com;<script>alert()</script>",
FILTER_VALIDATE_URL); // outputs JS alert box.
?>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73354&edit=1
Thread (3 messages)