Bug #76255 [Com]: parse_str() does not replace control characters
| From: | spam2 at rhsoft dot net | Date: | Sun, 28 Apr 2019 17:03:38 +0000 |
| Subject: | Bug #76255 [Com]: parse_str() does not replace control characters | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-220634@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76255&edit=1
ID: 76255
Comment by: spam2 at rhsoft dot net
Reported by: alex dot a dot pott at gmail dot com
Summary: parse_str() does not replace control characters
Status: Open
Type: Bug
Package: URL related
Operating System: OS X & Linux
PHP Version: 7.2.4
Block user comment: N
Private report: N
New Comment:
you souldn't pass random, unsanitized input to any function except one designed to sanitize
input
Previous Comments:
------------------------------------------------------------------------
[2019-04-28 16:47:41] duncan3dc@php.net
A null character isn't valid in a URL is it? Shouldn't it be encoded as %00 ?
------------------------------------------------------------------------
[2018-04-23 18:26:43] alex dot a dot pott at gmail dot com
Description:
------------
If you manually extract the query string from http://example.com?foo=bar&\x00foo=bar2&foo=bar3
and then use parse_str() on the result it is different than if you use parse_url() and then
parse_str(). This is loosely related to https://bugs.php.net/bug.php?id=66976.
Test script:
---------------
$url = "http://example.com?foo=bar&\x00foo=bar2&foo=bar3";
list($path, $query_string) = explode('?', $url, 2);
// Use parse_url() and then parse_str()
$parts = parse_url($url);
parse_str($parts['query'], $parsed_qs);
var_dump($parsed_qs);
// Ouptput: array(2) {
// ["foo"]=>
// string(4) "bar3"
// ["_foo"]=>
// string(4) "bar2"
//}
// Use parse_str()
parse_str($query_string, $parsed_qs);
var_dump($parsed_qs);
// Output: array(1) {
// ["foo"]=>
// string(3) "bar"
// }
Expected result:
----------------
I expect the second result to be the same as the first.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76255&edit=1