Bug #79618 [Opn->Nab]: PHP: checkdate does not validate input
| From: | peehaa@php.net | Date: | Thu, 21 May 2020 18:46:27 +0000 |
| Subject: | Bug #79618 [Opn->Nab]: PHP: checkdate does not validate input | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-227116@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79618&edit=1
ID: 79618
Updated by: peehaa@php.net
Reported by: adam dot engle at adventhealth dot com
Summary: PHP: checkdate does not validate input
-Status: Open
+Status: Not a bug
Type: Bug
Package: Date/time related
Operating System: Unix/OSX
PHP Version: 7.4.6
Block user comment: N
Private report: N
New Comment:
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
PHP casts the data.
For more information see https://www.php.net/manual/en/language.types.type-juggling.php
and https://www.php.net/manual/en/functions.arguments.php#functions.arguments.type-declaration.strict
Previous Comments:
------------------------------------------------------------------------
[2020-05-21 18:42:52] adam dot engle at adventhealth dot com
Description:
------------
---
From manual page: https://php.net/function.checkdate
---
echo "<?php var_dump(checkdate(12, 31,
'2000<script>alert(1)</script>'));" | php
bool(true)
echo "<?php var_dump(checkdate('12<script>alert(1)</script>', 31,
2000));" | php
bool(true)
Test script:
---------------
<?php
//Assume year is received via unvalidated input
$post_year_val = '2000<script>alert(1)</script>';
if (!checkdate(12, 1, $post_year_val)) {
$nowArray = getdate();
$month = $nowArray['mon'];
$year = $nowArray['year'];
} else {
$month = 12;
$year = $post_year_val;
}
$display_block = "<html><head/><body>";
$calendardate = $year."-".$month."-01";
$display_block .= $calendardate;
$display_block .= '</body></html>';
echo $display_block;
Expected result:
----------------
If input is not a valid integer as an input parameter, the function should fail closed, returning
false. Otherwise, unintended consequences could result if a developer assumes the input provided to
this function creates a valid date.
Actual result:
--------------
PHP 7.4.6 does provide a notice that it did not receive a well-formed int, however, it continues
processing anyway if a date can be devised from the string, failing open and returning true.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79618&edit=1