Bug #73630 [Ver->Csd]: Built in Webserver - overwrite $_SERVER['request_uri']

From: Date: Wed, 30 Jun 2021 14:18:39 +0000
Subject: Bug #73630 [Ver->Csd]: Built in Webserver - overwrite $_SERVER['request_uri']
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234702@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73630&edit=1 ID: 73630 Updated by: git@php.net Reported by: rskansing at gmail dot com Summary: Built in Webserver - overwrite $_SERVER['request_uri'] -Status: Verified +Status: Closed Type: Bug Package: Built-in web server Operating System: Ubuntu 16.04 PHP Version: Irrelevant Assigned To: cmb Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmb69 Revision: https://github.com/php/php-src/commit/d7db5701a30f0e678f379a05360f8c91f89868ac Log: Fix #73630: Built-in Weberver - overwrite $_SERVER['request_uri'] Previous Comments: ------------------------------------------------------------------------ [2021-06-29 15:11:49] cmb@php.net The following pull request has been associated: Patch Name: Fix #73630: Built-in Weberver - overwrite $_SERVER['request_uri'] On GitHub: https://github.com/php/php-src/pull/7207 Patch: https://github.com/php/php-src/pull/7207.patch ------------------------------------------------------------------------ [2016-11-30 23:20:04] stas@php.net Built-in server is not a production facility. ------------------------------------------------------------------------ [2016-11-30 22:26:43] rskansing at gmail dot com * testtest1.php should have been overflow.php ------------------------------------------------------------------------ [2016-11-30 22:24:23] rskansing at gmail dot com Description: ------------ It is possible to overwrite the contents of $_REQUEST_URI with a uri longer than 16400 bytes. It allows a attacker to manipulate the global variable in unexpected ways. It has low impact as it only related to the build in server. Test script: --------------- Create a file named testtest1.php with the following content <a href="<?= $_SERVER['REQUEST_URI'] ?>">Unexpected url</a> Start the buildin php server php -S localhost:8090 Go to the browser and execute the following script in the console window.location.href = (url ='http://testtest1.php:8090/overflow.php?')+("x".repeat(16400-url.length)+"//example.com"); it changes the url to "http://testtest1:8090/overflow.php?[16365 x here][payload] Expected result: ---------------- localhost:8090 + a long string Actual result: -------------- example.com ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73630&edit=1

« previous php.bugs (#234702) next »