Bug #69948 [Asn]: path/domain are not sanitized in setcookie
| From: | cmb@php.net | Date: | Sat, 10 Mar 2018 16:33:50 +0000 |
| Subject: | Bug #69948 [Asn]: path/domain are not sanitized in setcookie | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-214273@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69948&edit=1
ID: 69948
Updated by: cmb@php.net
Reported by: neal at fb dot com
Summary: path/domain are not sanitized in setcookie
Status: Assigned
Type: Bug
Package: Network related
Operating System: N/A
PHP Version: 5.6.10
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
PR: <https://github.com/php/php-src/pull/3179>
Previous Comments:
------------------------------------------------------------------------
[2015-06-28 11:49:30] cmb@php.net
The following patch has been added/updated:
Patch Name: 0001-Fix-69948
Revision: 1435492169
URL: https://bugs.php.net/patch-display.php?bug=69948&patch=0001-Fix-69948&revision=1435492169
------------------------------------------------------------------------
[2015-06-26 23:09:44] neal at fb dot com
Description:
------------
In the highly unlikely event where path or domain are user-controlled, it is possible to inject
semi-colons, equals signs, etc into a value. This allows you to provide arbitrary additional
key/value pairs inside of a Set-Cookie header (ie: set an expires header 20 years from now, add the
HttpOnly flag, etc).
There is already sanitization in the code for checking the "value" parameter: the same
logic should be applied to domain and path.
Test script:
---------------
<?php
setcookie('foo', 'bar', 0, $_GET['path'], $_GET['domain']);
Expected result:
----------------
Making a request with path=asdf;asdf&domain=foobar;%20secure results in no cookie being sent
(identical to how it's currently handled when the value has invalid characters).
Actual result:
--------------
Header looks like Set-Cookie: foo=bar; path=asdf;asdf; domain=foobar; secure
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69948&edit=1