Bug #77965 [Com]: not inlcuding php after <? allows user to access protected pages

From: Date: Fri, 03 May 2019 15:32:18 +0000
Subject: Bug #77965 [Com]: not inlcuding php after <? allows user to access protected pages
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220690@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77965&edit=1 ID: 77965 Comment by: drwho_who at yahoo dot com Reported by: drwho_who at yahoo dot com Summary: not inlcuding php after <? allows user to access protected pages Status: Not a bug Type: Bug Package: Session related Operating System: Windows Sefver 2016 PHP Version: 7.3.5 Block user comment: N Private report: N New Comment: Should be a major Security Flaw BUG. If a user can by pass the login due to a missing php, that's a bug. PHP should kill itself is code is not correct. MAJOR SECURITY HOLE Previous Comments: ------------------------------------------------------------------------ [2019-05-03 15:32:14] spam2 at rhsoft dot net how is it's PHP's fault when you just send a jeader but don't do an exit() after that and than have code after the if-clause which will happily execute because the server don#t bother about a redirect header it sends to the client? "<? allows user to access protected pages" is a terrible description anyways as well as "or the page completely error out if missing the php in <?" maybe you use only <? instead of <?php and short-open-atgs (which shouldn't be used for many years) are disabled on the server but who knows givenb that your descriptions are worded so bad ------------------------------------------------------------------------ [2019-05-03 15:27:35] peehaa@php.net Short open tags needs to be enable for that to work https://www.php.net/manual/en/ini.core.php#ini.short-open-tag If it's not enabled it's rendered as usual. ------------------------------------------------------------------------ [2019-05-03 15:23:25] drwho_who at yahoo dot com IF a user goes to the page with the code as shown, a link on the page will give them access to the site completely, and page, no forced logins. ------------------------------------------------------------------------ [2019-05-03 15:22:07] drwho_who at yahoo dot com Description: ------------ <? session_start(); ob_start(); if (isset($_SESSION['username']) && $_SESSION['jur']) { } else { header("Location: login.php"); } ?> Test script: --------------- <? session_start(); ob_start(); if (isset($_SESSION['username']) && $_SESSION['jur']) { } else { header("Location: login.php"); } ?> Expected result: ---------------- I would expect a user not to be able to get to this page, or the page completely error out if missing the php in <? ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77965&edit=1

« previous php.bugs (#220690) next »