Bug #17597: user supplied SID is given trust

From: Date: Tue, 04 Jun 2002 15:50:24 +0000
Subject: Bug #17597: user supplied SID is given trust
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-9476@lists.php.net to get a copy of this message
From: Giancarlo@navigare.net Operating system: PHP version: 4.2.1 PHP Bug Type: Session related Bug description: user supplied SID is given trust How is it possible that if a user provides a session in the URL, eg. mypage.php?PHPSESSID=spoofme even though php.ini says session.use_cookies =1 The session id is taken from the URL (but wasn't that the supposed behaviour of session.use_cookie=0 ?) and a session named 'spoofme' is created. Is it possible that is given trust to user input just on a paramount sensitive issue as the session ID? Would you run a cinema where you have to accept tickets issued by nobody-knows-who? This gravious security issue has been mentioned more than a year ago in the 'A study in scarlet' classical on php weaknessses, and it leads to nasty url injections and session hijacking. I am afraid this bus is a great feature for someone. -- Edit bug report at http://bugs.php.net/?id=17597&edit=1 -- Fixed in CVS: http://bugs.php.net/fix.php?id=17597&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=17597&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=17597&r=needtrace Try newer version: http://bugs.php.net/fix.php?id=17597&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=17597&r=support Expected behavior: http://bugs.php.net/fix.php?id=17597&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=17597&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=17597&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=17597&r=globals

« previous php.bugs (#9476) next »