Bug #16155 Updated: track_vars doesn't work unless register_globals is also set
From: rasmus@php.net Date: Tue, 19 Mar 2002 04:03:06 +0000 Subject: Bug #16155 Updated: track_vars doesn't work unless register_globals is also set References: 1 Groups: php.bugs Request: Send a blank email to php-bugs+get-2821@lists.php.net to get a copy of this message
ID: 16155 Updated by: rasmus@php.net Reported By: rlm@pricegrabber.com -Status: Open +Status: Feedback Bug Type: PHP options/info functions Operating System: RH 7.2 PHP Version: 4.1.2 New Comment: Uh, can anybody reproduce this? I certainly can't. HTTP_*_VARS are definitely on for me regardless of the register_globals setting. I suspect user error here. Previous Comments: ------------------------------------------------------------------------ [2002-03-18 18:18:54] rlm@pricegrabber.com The entire point of "register_globals Off" is to provide a mechanism to disable automatic registration of EGPCS (Environment, Get, Post, Cookie, System) variables. However, for this to be an effective strategy, scripts need access to these variables by other means. This SHOULD be the HTTP_*_VARS and _GET[], _POST[], etc. variables. But as of 4.1.2, track_vars (which is set on by default) doesn't work unless (1) register_globals is set On, AND (2) variables_order contains the particular type of variable you want. That is, unless you set variables_order to contain "G", neither _GET[] nor HTTP_GET_VARS[] will be contain the results from the GET request, but if variables_order does contain "G", they *will*. Considering the number of exploits caused by namespace pollution that register_globals has been accused (and convicted) of, this is about as serious a security bug as I can think of. I will be digging through the source tree to come up with a patch. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=16155&edit=1
Thread (21 messages)
- Bug #16155 Updated: track_vars doesn't work unless register_globals is also set
- Bug #16155 Updated: track_vars doesn't work unless register_globals is also set
- Bug #16155 Updated: track_vars doesn't work unless register_globals is also set
- Bug #16155 Updated: track_vars doesn't work unless register_globals is also set
- Bug #16155 Updated: Some predefined variables allow GET overwrite
- Bug #16155 Updated: Some predefined variables allow GET overwrite
- Bug #16155 Updated: _GET[] &c. not set unless variables_order position set
- Bug #16155 Updated: track_vars doesn't work unless register_globals is also set
- Bug #16155 Updated: track_vars doesn't work unless register_globals is also set
- Bug #16155 Updated: track_vars doesn't work unless register_globals is also set
- Bug #16155 Updated: track_vars doesn't work unless register_globals is also set
- Bug #16155 Updated: track_vars doesn't work unless register_globals is also set
- Bug #16155 Updated: variables_order affects existence of php predefined variables
- Bug #16155 Updated: variables_order affects existence of php predefined variables
- Bug #16155 Updated: variables_order affects existence of php predefined variables
- Bug #16155 Updated: variables_order affects existence of php predefined variables
- Bug #16155 Updated: variables_order affects existence of php predefined variables
- #16155 [Opn]: variables_order affects existence of php predefined variables
- #16155 [Com]: variables_order affects existence of php predefined variables
- Req #16155 [Opn->Bgs]: variables_order affects existence of php predefined variables
| « previous | php.bugs (#2821) | next » |
|---|