Bug #16361 Updated: user can crash apache child entering incorrect session name

From: Date: Sat, 30 Mar 2002 23:35:49 +0000
Subject: Bug #16361 Updated: user can crash apache child entering incorrect session name
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-3662@lists.php.net to get a copy of this message
ID: 16361 Updated by: yohgaki@php.net Reported By: samm@os2.ru Status: Open Bug Type: Session related Operating System: Windows NT, OS/2 PHP Version: 4.1.2 New Comment: Thanks for reporting, but this has been reported already. IIRC. Previous Comments: ------------------------------------------------------------------------ [2002-03-30 11:58:59] samm@os2.ru To reproduce bug do this test: 1) Turn off cookies at browser. 2) run file: <? session_name ("SESSID"); session_set_cookie_params (3600); session_register("test"); //registring tracks variable. if (!isset($test)) $test=1; $test=$test++; echo '<a href="'.$PHP_SELF.'?SESSID='.session_id().'">test</a>'; echo '<br><a href="'.$PHP_SELF.'?SESSID=c:\123">test2</a>'; ?> 3) Click on a "test2" link 4) Apache child will crash and php will write message like Warning: Failed to write session data (files). Please verify that the current setting of session.save_path is correct (/tmp) in Unknown on line 0 Testes on OS/2 (PHP 4.1.2) and win32 (PHP 4.1.1). PHP is installed as Apache module. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=16361&edit=1

« previous php.bugs (#3662) next »