Bug #3517: HTTP_COOKIE_VARS, HTTP_POST_VARS, HTTP_GET_VARS open to manipulation

From: Date: Thu, 17 Feb 2000 09:56:29 +0000
Subject: Bug #3517: HTTP_COOKIE_VARS, HTTP_POST_VARS, HTTP_GET_VARS open to manipulation
Groups: php.dev 
Request: Send a blank email to php-dev+get-15632@lists.php.net to get a copy of this message
From: naklar@altavista.net Operating system: Windows CGI version, probably all others PHP version: 3.0.14 PHP Bug Type: Misbehaving function Bug description: HTTP_COOKIE_VARS, HTTP_POST_VARS, HTTP_GET_VARS open to manipulation HTTP_COOKIE_VARS,HTTP_POST_VARS,HTTP_GET_VARS are useful to determine the origin of a global Variable. Unfortunately, a statement like this: www.domain.tld?HTTP_COOKIE_VARS=nothing destroys the array. This enables possible attacks and malfunctions against any session management, which relies on the evaluation of the array data. Example (with error_reporting = 15) 1. "normal behaviour": URL: http://test/_sessiontest/httpcookievars.php <?php SetCookie("testcookie", "identifier", 0); reset($HTTP_COOKIE_VARS); while (list ( $k,$v)=each ($HTTP_COOKIE_VARS)) {echo "<br>$k = $v";} ?> Cookie is set/was already set. Result is ok: testcookie = identifier 2. "misbehaviour / attack": URL: http://test/_sessiontest/httpcookievars.php?HTTP_COOKIE_VARS=nix Cookie is set/was already set. Result is not ok: Warning: Variable passed to reset() is not an array or object in d:\www\test\_sessiontest\httpcookievars.php on line 4 Warning: Variable passed to each() is not an array or object in d:\www\test\_sessiontest\httpcookievars.php on line 5 The results can be reproduced. Possible Solution: The mentioned Arrays should be under any circumstances READ/ONLY to avoid such errors. Thx. oK

« previous php.dev (#15632) next »