PHP 4.0 Bug #6660 Updated: PHP magic variables can be overridden by GPC variables

From: Date: Tue, 12 Sep 2000 04:26:55 +0000
Subject: PHP 4.0 Bug #6660 Updated: PHP magic variables can be overridden by GPC variables
Groups: php.dev 
Request: Send a blank email to php-dev+get-32933@lists.php.net to get a copy of this message
ID: 6660 Updated by: rasmus Reported By: jon+php-dev@unequivocal.co.uk Status: Closed Bug Type: *General Issues Assigned To: Comments: Fixed for 4.0.3 Previous Comments: --------------------------------------------------------------------------- [2000-09-11 21:29:34] jon+php-dev@unequivocal.co.uk Hmm, actually, 4.0.3RC1 seems to improve this. I am not sure what has changed though, so I can't check for sure. --------------------------------------------------------------------------- [2000-09-11 20:12:25] jon+php-dev@unequivocal.co.uk This is a potential security issue. If register_globals is on, then PHP magic variables (HTTP_GET_VARS, HTTP_POST_VARS, etc) can be faked by remote web users. This is particularly important in the case of HTTP_ENV_VARS and HTTP_POST_FILES, which the script author may expect to come from a local source. e.g. http://www.example.com/example.php?HTTP_POST_FILES[file]=/etc/passwd All the variables in http://www.php.net/manual/language.variables.predefined.php should be protected from being set by GPC variables, presumably in php_register_variables_ex. (Some variables cannot be overridden because they are set later to the correct values, but this is not good to rely on.) (Yes, I know you have added 'is_uploaded_files'. I think this should be fixed anyway.) --------------------------------------------------------------------------- Full Bug description available at: http://bugs.php.net/?id=6660

« previous php.dev (#32933) next »