Bug #77965 [Opn->Nab]: not inlcuding php after <? allows user to access protected pages
| From: | peehaa@php.net | Date: | Fri, 03 May 2019 15:27:35 +0000 |
| Subject: | Bug #77965 [Opn->Nab]: not inlcuding php after <? allows user to access protected pages | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-220688@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77965&edit=1
ID: 77965
Updated by: peehaa@php.net
Reported by: drwho_who at yahoo dot com
Summary: not inlcuding php after <? allows user to access
protected pages
-Status: Open
+Status: Not a bug
Type: Bug
Package: Session related
Operating System: Windows Sefver 2016
PHP Version: 7.3.5
Block user comment: N
Private report: N
New Comment:
Short open tags needs to be enable for that to work https://www.php.net/manual/en/ini.core.php#ini.short-open-tag
If it's not enabled it's rendered as usual.
Previous Comments:
------------------------------------------------------------------------
[2019-05-03 15:23:25] drwho_who at yahoo dot com
IF a user goes to the page with the code as shown, a link on the page will give them access to the
site completely, and page, no forced logins.
------------------------------------------------------------------------
[2019-05-03 15:22:07] drwho_who at yahoo dot com
Description:
------------
<?
session_start();
ob_start();
if (isset($_SESSION['username']) && $_SESSION['jur']) {
} else {
header("Location: login.php");
}
?>
Test script:
---------------
<?
session_start();
ob_start();
if (isset($_SESSION['username']) && $_SESSION['jur']) {
} else {
header("Location: login.php");
}
?>
Expected result:
----------------
I would expect a user not to be able to get to this page, or the page completely error out if
missing the php in <?
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77965&edit=1