Bug #69948 [Asn]: path/domain are not sanitized in setcookie

From: Date: Sat, 10 Mar 2018 16:33:50 +0000
Subject: Bug #69948 [Asn]: path/domain are not sanitized in setcookie
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214273@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69948&edit=1 ID: 69948 Updated by: cmb@php.net Reported by: neal at fb dot com Summary: path/domain are not sanitized in setcookie Status: Assigned Type: Bug Package: Network related Operating System: N/A PHP Version: 5.6.10 Assigned To: cmb Block user comment: N Private report: N New Comment: PR: <https://github.com/php/php-src/pull/3179> Previous Comments: ------------------------------------------------------------------------ [2015-06-28 11:49:30] cmb@php.net The following patch has been added/updated: Patch Name: 0001-Fix-69948 Revision: 1435492169 URL: https://bugs.php.net/patch-display.php?bug=69948&patch=0001-Fix-69948&revision=1435492169 ------------------------------------------------------------------------ [2015-06-26 23:09:44] neal at fb dot com Description: ------------ In the highly unlikely event where path or domain are user-controlled, it is possible to inject semi-colons, equals signs, etc into a value. This allows you to provide arbitrary additional key/value pairs inside of a Set-Cookie header (ie: set an expires header 20 years from now, add the HttpOnly flag, etc). There is already sanitization in the code for checking the "value" parameter: the same logic should be applied to domain and path. Test script: --------------- <?php setcookie('foo', 'bar', 0, $_GET['path'], $_GET['domain']); Expected result: ---------------- Making a request with path=asdf;asdf&domain=foobar;%20secure results in no cookie being sent (identical to how it's currently handled when the value has invalid characters). Actual result: -------------- Header looks like Set-Cookie: foo=bar; path=asdf;asdf; domain=foobar; secure ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=69948&edit=1

« previous php.bugs (#214273) next »