Bug #77965 [Nab]: not inlcuding php after <? allows user to access protected pages

From: Date: Fri, 03 May 2019 15:43:08 +0000
Subject: Bug #77965 [Nab]: not inlcuding php after <? allows user to access protected pages
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220692@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77965&edit=1 ID: 77965 User updated by: drwho_who at yahoo dot com Reported by: drwho_who at yahoo dot com Summary: not inlcuding php after <? allows user to access protected pages Status: Not a bug Type: Bug Package: Session related Operating System: Windows Sefver 2016 PHP Version: 7.3.5 Block user comment: N Private report: N New Comment: wow....grow up Previous Comments: ------------------------------------------------------------------------ [2019-05-03 15:38:04] lulz at lel dot lol There are some other types of major hole going on around here by the looks of things ------------------------------------------------------------------------ [2019-05-03 15:32:18] drwho_who at yahoo dot com Should be a major Security Flaw BUG. If a user can by pass the login due to a missing php, that's a bug. PHP should kill itself is code is not correct. MAJOR SECURITY HOLE ------------------------------------------------------------------------ [2019-05-03 15:32:14] spam2 at rhsoft dot net how is it's PHP's fault when you just send a jeader but don't do an exit() after that and than have code after the if-clause which will happily execute because the server don#t bother about a redirect header it sends to the client? "<? allows user to access protected pages" is a terrible description anyways as well as "or the page completely error out if missing the php in <?" maybe you use only <? instead of <?php and short-open-atgs (which shouldn't be used for many years) are disabled on the server but who knows givenb that your descriptions are worded so bad ------------------------------------------------------------------------ [2019-05-03 15:27:35] peehaa@php.net Short open tags needs to be enable for that to work https://www.php.net/manual/en/ini.core.php#ini.short-open-tag If it's not enabled it's rendered as usual. ------------------------------------------------------------------------ [2019-05-03 15:23:25] drwho_who at yahoo dot com IF a user goes to the page with the code as shown, a link on the page will give them access to the site completely, and page, no forced logins. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77965 -- Edit this bug report at https://bugs.php.net/bug.php?id=77965&edit=1

« previous php.bugs (#220692) next »