Bug #3517 Updated: HTTP_COOKIE_VARS, HTTP_POST_VARS, HTTP_GET_VARS open to manipulation
| From: | Bug Database | Date: | Thu, 17 Feb 2000 19:11:05 +0000 |
| Subject: | Bug #3517 Updated: HTTP_COOKIE_VARS, HTTP_POST_VARS, HTTP_GET_VARS open to manipulation | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-15657@lists.php.net to get a copy of this message | ||
ID: 3517
Updated by: joey
Reported By: naklar@altavista.net
Status: Open
Bug Type: Misbehaving function
Assigned To:
Comments:
This seems to only be a concern if all you are doing for "session management" is testing
/IF/ a variable is set,
rather than using sessions the way that (AFAIK) they are meant to be used...ie, make sure that
whatever
session vars are passed by user still exist, either in DB or filesystem, however you implemented
your sess.
management.
There are times when I actually dig into the HTTP_POST_VARS for very good reasons, as do some
others,
so making these read only is not, IMO, a good idea.
I am not denying that this /may/ be a security risk to some degree, but your bug report
A) Does not (IMO) give a valid example of /HOW/ this could be abused
B) Your suggested fix does not seem to be the best way around such issues.
Full Bug description available at: http://bugs.php.net/?id=3517