Sec Bug->Bug #73630 [Opn]: Buildin-server - Overwrite $_SERVER['request_uri']

From: Date: Wed, 30 Nov 2016 23:19:38 +0000
Subject: Sec Bug->Bug #73630 [Opn]: Buildin-server - Overwrite $_SERVER['request_uri']
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205702@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73630&edit=1 ID: 73630 Updated by: stas@php.net Reported by: rskansing at gmail dot com Summary: Buildin-server - Overwrite $_SERVER['request_uri'] Status: Open -Type: Security +Type: Bug Package: Built-in web server Operating System: Ubuntu 16.04 PHP Version: Irrelevant Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2016-11-30 22:26:43] rskansing at gmail dot com * testtest1.php should have been overflow.php ------------------------------------------------------------------------ [2016-11-30 22:24:23] rskansing at gmail dot com Description: ------------ It is possible to overwrite the contents of $_REQUEST_URI with a uri longer than 16400 bytes. It allows a attacker to manipulate the global variable in unexpected ways. It has low impact as it only related to the build in server. Test script: --------------- Create a file named testtest1.php with the following content <a href="<?= $_SERVER['REQUEST_URI'] ?>">Unexpected url</a> Start the buildin php server php -S localhost:8090 Go to the browser and execute the following script in the console window.location.href = (url ='http://testtest1.php:8090/overflow.php?')+("x".repeat(16400-url.length)+"//example.com"); it changes the url to "http://testtest1:8090/overflow.php?[16365 x here][payload] Expected result: ---------------- localhost:8090 + a long string Actual result: -------------- example.com ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73630&edit=1

« previous php.bugs (#205702) next »