Bug #77965 [Com]: not inlcuding php after <? allows user to access protected pages
| From: | daverandom@php.net | Date: | Fri, 03 May 2019 15:47:50 +0000 |
| Subject: | Bug #77965 [Com]: not inlcuding php after <? allows user to access protected pages | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-220695@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77965&edit=1
ID: 77965
Comment by: daverandom@php.net
Reported by: drwho_who at yahoo dot com
Summary: not inlcuding php after <? allows user to access
protected pages
Status: Not a bug
Type: Bug
Package: Session related
Operating System: Windows Sefver 2016
PHP Version: 7.3.5
Block user comment: Y
Private report: N
New Comment:
I've closed comments on this before it gets any worse.
Previous Comments:
------------------------------------------------------------------------
[2019-05-03 15:47:03] daverandom@php.net
You are correct, it is a security hole, which is why short tags are in the process of being removed
from the language https://wiki.php.net/rfc/deprecate_php_short_tags
The solution to the problem is simply to not ever use short open tags.
------------------------------------------------------------------------
[2019-05-03 15:45:45] spam2 at rhsoft dot net
> PHP should kill itself is code is not correct
> MAJOR SECURITY HOLE
bullshit!
when short_opentags is disabled anything with <? ?> is not code at all
hence don't rely on random configs which can be different on every server and than blame php
because you are too lazy write proper <?php as anybody does for years now
RTFM: https://www.php.net/manual/en/ini.core.php#ini.short-open-tag
------------------------------------------------------------------------
[2019-05-03 15:43:08] drwho_who at yahoo dot com
wow....grow up
------------------------------------------------------------------------
[2019-05-03 15:38:04] lulz at lel dot lol
There are some other types of major hole going on around here by the looks of things
------------------------------------------------------------------------
[2019-05-03 15:32:18] drwho_who at yahoo dot com
Should be a major Security Flaw BUG.
If a user can by pass the login due to a missing php, that's a bug.
PHP should kill itself is code is not correct.
MAJOR SECURITY HOLE
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77965
--
Edit this bug report at https://bugs.php.net/bug.php?id=77965&edit=1