Bug #77965 [Nab]: not inlcuding php after <? allows user to access protected pages
| From: | daverandom@php.net | Date: | Fri, 03 May 2019 15:47:03 +0000 |
| Subject: | Bug #77965 [Nab]: not inlcuding php after <? allows user to access protected pages | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-220694@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77965&edit=1
ID: 77965
Updated by: daverandom@php.net
Reported by: drwho_who at yahoo dot com
Summary: not inlcuding php after <? allows user to access
protected pages
Status: Not a bug
Type: Bug
Package: Session related
Operating System: Windows Sefver 2016
PHP Version: 7.3.5
-Block user comment: No
+Block user comment: Yes
Private report: N
New Comment:
You are correct, it is a security hole, which is why short tags are in the process of being removed
from the language https://wiki.php.net/rfc/deprecate_php_short_tags
The solution to the problem is simply to not ever use short open tags.
Previous Comments:
------------------------------------------------------------------------
[2019-05-03 15:45:45] spam2 at rhsoft dot net
> PHP should kill itself is code is not correct
> MAJOR SECURITY HOLE
bullshit!
when short_opentags is disabled anything with <? ?> is not code at all
hence don't rely on random configs which can be different on every server and than blame php
because you are too lazy write proper <?php as anybody does for years now
RTFM: https://www.php.net/manual/en/ini.core.php#ini.short-open-tag
------------------------------------------------------------------------
[2019-05-03 15:43:08] drwho_who at yahoo dot com
wow....grow up
------------------------------------------------------------------------
[2019-05-03 15:38:04] lulz at lel dot lol
There are some other types of major hole going on around here by the looks of things
------------------------------------------------------------------------
[2019-05-03 15:32:18] drwho_who at yahoo dot com
Should be a major Security Flaw BUG.
If a user can by pass the login due to a missing php, that's a bug.
PHP should kill itself is code is not correct.
MAJOR SECURITY HOLE
------------------------------------------------------------------------
[2019-05-03 15:32:14] spam2 at rhsoft dot net
how is it's PHP's fault when you just send a jeader but don't do an exit() after that
and than have code after the if-clause which will happily execute because the server don#t bother
about a redirect header it sends to the client?
"<? allows user to access protected pages" is a terrible description anyways as well as
"or the page completely error out if missing the php in <?"
maybe you use only <? instead of <?php and short-open-atgs (which shouldn't be used for
many years) are disabled on the server but who knows givenb that your descriptions are worded so bad
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77965
--
Edit this bug report at https://bugs.php.net/bug.php?id=77965&edit=1