Bug #3517 Updated: HTTP_COOKIE_VARS, HTTP_POST_VARS, HTTP_GET_VARS open to manipulation

From: Date: Thu, 17 Feb 2000 19:11:05 +0000
Subject: Bug #3517 Updated: HTTP_COOKIE_VARS, HTTP_POST_VARS, HTTP_GET_VARS open to manipulation
Groups: php.dev 
Request: Send a blank email to php-dev+get-15657@lists.php.net to get a copy of this message
ID: 3517 Updated by: joey Reported By: naklar@altavista.net Status: Open Bug Type: Misbehaving function Assigned To: Comments: This seems to only be a concern if all you are doing for "session management" is testing /IF/ a variable is set, rather than using sessions the way that (AFAIK) they are meant to be used...ie, make sure that whatever session vars are passed by user still exist, either in DB or filesystem, however you implemented your sess. management. There are times when I actually dig into the HTTP_POST_VARS for very good reasons, as do some others, so making these read only is not, IMO, a good idea. I am not denying that this /may/ be a security risk to some degree, but your bug report A) Does not (IMO) give a valid example of /HOW/ this could be abused B) Your suggested fix does not seem to be the best way around such issues. Full Bug description available at: http://bugs.php.net/?id=3517

« previous php.dev (#15657) next »