PHP 4.0 Bug #6660: PHP magic variables can be overridden by GPC variables
| From: | jon+php-dev at unequivocal dot co dot uk | Date: | Tue, 12 Sep 2000 00:12:25 +0000 |
| Subject: | PHP 4.0 Bug #6660: PHP magic variables can be overridden by GPC variables | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-32899@lists.php.net to get a copy of this message | ||
From: jon+php-dev@unequivocal.co.uk
Operating system: N/A
PHP version: 4.0 Latest CVS (11/09/2000)
PHP Bug Type: *General Issues
Bug description: PHP magic variables can be overridden by GPC variables
This is a potential security issue.
If register_globals is on, then PHP magic variables (HTTP_GET_VARS, HTTP_POST_VARS, etc) can be
faked by remote web users. This is particularly important in the case of HTTP_ENV_VARS and
HTTP_POST_FILES, which the script author may expect to come from a local source.
e.g.
http://www.example.com/example.php?HTTP_POST_FILES[file]=/etc/passwd
All the variables in http://www.php.net/manual/language.variables.predefined.php
should be protected from being set by GPC variables, presumably in php_register_variables_ex. (Some
variables cannot be overridden because they are set later to the correct values, but this is not
good to rely on.)
(Yes, I know you have added 'is_uploaded_files'. I think this should be fixed anyway.)