Bug #77965 [Nab]: not inlcuding php after <? allows user to access protected pages

From: Date: Fri, 03 May 2019 15:47:03 +0000
Subject: Bug #77965 [Nab]: not inlcuding php after <? allows user to access protected pages
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220694@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77965&edit=1 ID: 77965 Updated by: daverandom@php.net Reported by: drwho_who at yahoo dot com Summary: not inlcuding php after <? allows user to access protected pages Status: Not a bug Type: Bug Package: Session related Operating System: Windows Sefver 2016 PHP Version: 7.3.5 -Block user comment: No +Block user comment: Yes Private report: N New Comment: You are correct, it is a security hole, which is why short tags are in the process of being removed from the language https://wiki.php.net/rfc/deprecate_php_short_tags The solution to the problem is simply to not ever use short open tags. Previous Comments: ------------------------------------------------------------------------ [2019-05-03 15:45:45] spam2 at rhsoft dot net > PHP should kill itself is code is not correct > MAJOR SECURITY HOLE bullshit! when short_opentags is disabled anything with <? ?> is not code at all hence don't rely on random configs which can be different on every server and than blame php because you are too lazy write proper <?php as anybody does for years now RTFM: https://www.php.net/manual/en/ini.core.php#ini.short-open-tag ------------------------------------------------------------------------ [2019-05-03 15:43:08] drwho_who at yahoo dot com wow....grow up ------------------------------------------------------------------------ [2019-05-03 15:38:04] lulz at lel dot lol There are some other types of major hole going on around here by the looks of things ------------------------------------------------------------------------ [2019-05-03 15:32:18] drwho_who at yahoo dot com Should be a major Security Flaw BUG. If a user can by pass the login due to a missing php, that's a bug. PHP should kill itself is code is not correct. MAJOR SECURITY HOLE ------------------------------------------------------------------------ [2019-05-03 15:32:14] spam2 at rhsoft dot net how is it's PHP's fault when you just send a jeader but don't do an exit() after that and than have code after the if-clause which will happily execute because the server don#t bother about a redirect header it sends to the client? "<? allows user to access protected pages" is a terrible description anyways as well as "or the page completely error out if missing the php in <?" maybe you use only <? instead of <?php and short-open-atgs (which shouldn't be used for many years) are disabled on the server but who knows givenb that your descriptions are worded so bad ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77965 -- Edit this bug report at https://bugs.php.net/bug.php?id=77965&edit=1

« previous php.bugs (#220694) next »