Bug #77965 [Com]: not inlcuding php after <? allows user to access protected pages

From: Date: Fri, 03 May 2019 15:47:50 +0000
Subject: Bug #77965 [Com]: not inlcuding php after <? allows user to access protected pages
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220695@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77965&edit=1 ID: 77965 Comment by: daverandom@php.net Reported by: drwho_who at yahoo dot com Summary: not inlcuding php after <? allows user to access protected pages Status: Not a bug Type: Bug Package: Session related Operating System: Windows Sefver 2016 PHP Version: 7.3.5 Block user comment: Y Private report: N New Comment: I've closed comments on this before it gets any worse. Previous Comments: ------------------------------------------------------------------------ [2019-05-03 15:47:03] daverandom@php.net You are correct, it is a security hole, which is why short tags are in the process of being removed from the language https://wiki.php.net/rfc/deprecate_php_short_tags The solution to the problem is simply to not ever use short open tags. ------------------------------------------------------------------------ [2019-05-03 15:45:45] spam2 at rhsoft dot net > PHP should kill itself is code is not correct > MAJOR SECURITY HOLE bullshit! when short_opentags is disabled anything with <? ?> is not code at all hence don't rely on random configs which can be different on every server and than blame php because you are too lazy write proper <?php as anybody does for years now RTFM: https://www.php.net/manual/en/ini.core.php#ini.short-open-tag ------------------------------------------------------------------------ [2019-05-03 15:43:08] drwho_who at yahoo dot com wow....grow up ------------------------------------------------------------------------ [2019-05-03 15:38:04] lulz at lel dot lol There are some other types of major hole going on around here by the looks of things ------------------------------------------------------------------------ [2019-05-03 15:32:18] drwho_who at yahoo dot com Should be a major Security Flaw BUG. If a user can by pass the login due to a missing php, that's a bug. PHP should kill itself is code is not correct. MAJOR SECURITY HOLE ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77965 -- Edit this bug report at https://bugs.php.net/bug.php?id=77965&edit=1

« previous php.bugs (#220695) next »