Bug #77074 [Opn]: david@grudl.com

From: Date: Sat, 27 Oct 2018 19:31:53 +0000
Subject: Bug #77074 [Opn]: david@grudl.com
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217720@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77074&edit=1 ID: 77074 User updated by: david at grudl dot com Reported by: david at grudl dot com -Summary: XSS through error messages +Summary: david@grudl.com Status: Open Type: Bug Package: Output Control -PHP Version: 7.3.0RC4 +PHP Version: 5.6.5 Block user comment: N Private report: N New Comment: Yes, html_errors is enabled. (Sorry for wrong description, autofilling in browser surprised me ;-) Previous Comments: ------------------------------------------------------------------------ [2018-10-27 19:30:39] requinix@php.net The escaping only happens for E_ERROR and E_PARSE. https://github.com/php/php-src/blob/php-7.3.0RC4/main/main.c#L1336 ------------------------------------------------------------------------ [2018-10-27 19:20:46] nikic@php.net We're definitely applying htmlspecialchars to errors in html_errors mode. Can you please double check that it is really enabled (e.g. by printing the html_errors ini setting in the same script you are testing the error message)? ------------------------------------------------------------------------ [2018-10-27 19:08:57] david at grudl dot com Description: ------------ Displaying error messages is vulnerable to XSS, although the 'html_errors' is enabled. Solution is to convert especial charactes < & in error message (ie to use htmlspecialchars) Test script: --------------- <?php echo ${'<script>alert(123);</script>'}; Expected result: ---------------- In web browser it should not pop up the alert window, but it should report: "Notice: Undefined variable: <script>alert(123);</script> in test.php on line 3 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77074&edit=1

« previous php.bugs (#217720) next »