Bug #77074 [Opn]: david@grudl.com
| From: | david at grudl dot com | Date: | Sat, 27 Oct 2018 19:31:53 +0000 |
| Subject: | Bug #77074 [Opn]: david@grudl.com | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-217720@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77074&edit=1
ID: 77074
User updated by: david at grudl dot com
Reported by: david at grudl dot com
-Summary: XSS through error messages
+Summary: david@grudl.com
Status: Open
Type: Bug
Package: Output Control
-PHP Version: 7.3.0RC4
+PHP Version: 5.6.5
Block user comment: N
Private report: N
New Comment:
Yes, html_errors is enabled.
(Sorry for wrong description, autofilling in browser surprised me ;-)
Previous Comments:
------------------------------------------------------------------------
[2018-10-27 19:30:39] requinix@php.net
The escaping only happens for E_ERROR and E_PARSE.
https://github.com/php/php-src/blob/php-7.3.0RC4/main/main.c#L1336
------------------------------------------------------------------------
[2018-10-27 19:20:46] nikic@php.net
We're definitely applying htmlspecialchars to errors in html_errors mode. Can you please double
check that it is really enabled (e.g. by printing the html_errors ini setting in the same script you
are testing the error message)?
------------------------------------------------------------------------
[2018-10-27 19:08:57] david at grudl dot com
Description:
------------
Displaying error messages is vulnerable to XSS, although the 'html_errors' is enabled.
Solution is to convert especial charactes < & in error message (ie to use htmlspecialchars)
Test script:
---------------
<?php
echo ${'<script>alert(123);</script>'};
Expected result:
----------------
In web browser it should not pop up the alert window, but it should report:
"Notice: Undefined variable: <script>alert(123);</script> in test.php on line 3
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77074&edit=1