PHP 4.0 Bug #6660 Updated: PHP magic variables can be overridden by GPC variables
| From: | Bug Database | Date: | Tue, 12 Sep 2000 04:26:55 +0000 |
| Subject: | PHP 4.0 Bug #6660 Updated: PHP magic variables can be overridden by GPC variables | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-32933@lists.php.net to get a copy of this message | ||
ID: 6660
Updated by: rasmus
Reported By: jon+php-dev@unequivocal.co.uk
Status: Closed
Bug Type: *General Issues
Assigned To:
Comments:
Fixed for 4.0.3
Previous Comments:
---------------------------------------------------------------------------
[2000-09-11 21:29:34] jon+php-dev@unequivocal.co.uk
Hmm, actually, 4.0.3RC1 seems to improve this. I am not sure what has changed though, so I
can't check for sure.
---------------------------------------------------------------------------
[2000-09-11 20:12:25] jon+php-dev@unequivocal.co.uk
This is a potential security issue.
If register_globals is on, then PHP magic variables (HTTP_GET_VARS, HTTP_POST_VARS, etc) can be
faked by remote web users. This is particularly important in the case of HTTP_ENV_VARS and
HTTP_POST_FILES, which the script author may expect to come from a local source.
e.g.
http://www.example.com/example.php?HTTP_POST_FILES[file]=/etc/passwd
All the variables in http://www.php.net/manual/language.variables.predefined.php
should be protected from being set by GPC variables, presumably in php_register_variables_ex. (Some
variables cannot be overridden because they are set later to the correct values, but this is not
good to rely on.)
(Yes, I know you have added 'is_uploaded_files'. I think this should be fixed anyway.)
---------------------------------------------------------------------------
Full Bug description available at: http://bugs.php.net/?id=6660