PHP 4.0 Bug #6660: PHP magic variables can be overridden by GPC variables

From: Date: Tue, 12 Sep 2000 00:12:25 +0000
Subject: PHP 4.0 Bug #6660: PHP magic variables can be overridden by GPC variables
Groups: php.dev 
Request: Send a blank email to php-dev+get-32899@lists.php.net to get a copy of this message
From: jon+php-dev@unequivocal.co.uk Operating system: N/A PHP version: 4.0 Latest CVS (11/09/2000) PHP Bug Type: *General Issues Bug description: PHP magic variables can be overridden by GPC variables This is a potential security issue. If register_globals is on, then PHP magic variables (HTTP_GET_VARS, HTTP_POST_VARS, etc) can be faked by remote web users. This is particularly important in the case of HTTP_ENV_VARS and HTTP_POST_FILES, which the script author may expect to come from a local source. e.g. http://www.example.com/example.php?HTTP_POST_FILES[file]=/etc/passwd All the variables in http://www.php.net/manual/language.variables.predefined.php should be protected from being set by GPC variables, presumably in php_register_variables_ex. (Some variables cannot be overridden because they are set later to the correct values, but this is not good to rely on.) (Yes, I know you have added 'is_uploaded_files'. I think this should be fixed anyway.)

« previous php.dev (#32899) next »