Bug #79618 [Opn->Nab]: PHP: checkdate does not validate input

From: Date: Thu, 21 May 2020 18:46:27 +0000
Subject: Bug #79618 [Opn->Nab]: PHP: checkdate does not validate input
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-227116@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79618&edit=1 ID: 79618 Updated by: peehaa@php.net Reported by: adam dot engle at adventhealth dot com Summary: PHP: checkdate does not validate input -Status: Open +Status: Not a bug Type: Bug Package: Date/time related Operating System: Unix/OSX PHP Version: 7.4.6 Block user comment: N Private report: N New Comment: Thank you for taking the time to write to us, but this is not a bug. Please double-check the documentation available at http://www.php.net/manual/ and the instructions on how to report a bug at http://bugs.php.net/how-to-report.php PHP casts the data. For more information see https://www.php.net/manual/en/language.types.type-juggling.php and https://www.php.net/manual/en/functions.arguments.php#functions.arguments.type-declaration.strict Previous Comments: ------------------------------------------------------------------------ [2020-05-21 18:42:52] adam dot engle at adventhealth dot com Description: ------------ --- From manual page: https://php.net/function.checkdate --- echo "<?php var_dump(checkdate(12, 31, '2000<script>alert(1)</script>'));" | php bool(true) echo "<?php var_dump(checkdate('12<script>alert(1)</script>', 31, 2000));" | php bool(true) Test script: --------------- <?php //Assume year is received via unvalidated input $post_year_val = '2000<script>alert(1)</script>'; if (!checkdate(12, 1, $post_year_val)) { $nowArray = getdate(); $month = $nowArray['mon']; $year = $nowArray['year']; } else { $month = 12; $year = $post_year_val; } $display_block = "<html><head/><body>"; $calendardate = $year."-".$month."-01"; $display_block .= $calendardate; $display_block .= '</body></html>'; echo $display_block; Expected result: ---------------- If input is not a valid integer as an input parameter, the function should fail closed, returning false. Otherwise, unintended consequences could result if a developer assumes the input provided to this function creates a valid date. Actual result: -------------- PHP 7.4.6 does provide a notice that it did not receive a well-formed int, however, it continues processing anyway if a date can be devised from the string, failing open and returning true. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=79618&edit=1

« previous php.bugs (#227116) next »