PHP 4.0 Bug #7044 Updated: Session file created when using bogus SESSIONID

From: Date: Thu, 05 Oct 2000 23:28:29 +0000
Subject: PHP 4.0 Bug #7044 Updated: Session file created when using bogus SESSIONID
Groups: php.dev 
Request: Send a blank email to php-dev+get-34306@lists.php.net to get a copy of this message
ID: 7044 User Update by: kimmel@tricos.com Status: Open Bug Type: *Session related Description: Session file created when using bogus SESSIONID JFYI: I'm using IIS/PWS (SP5) with the PHP CGI version. Previous Comments: --------------------------------------------------------------------------- [2000-10-05 17:27:27] kimmel@tricos.com I'm using the <?=SID?> feature to automatically append the corresponding session ID to every link, so that no cookies are required to use the site. A sample URL as visible on the browser´s address bar: http://webtest/human_resources.phtml?SESSIONID=cca7f03abde2c33077df25999850d6dc Now if I change the SESSIONID parameter to something really stupid PHP simply creates a file with exactly that name regardless if a session with that SESSIONID has never been created before by session_start(): http://webtest/human_resources.phtml?SESSIONID=stupidsessionid creates the file "sessstupidsessionid" in the session directory. Why? This way someone could fill up the whole directory! --------------------------------------------------------------------------- Full Bug description available at: http://bugs.php.net/?id=7044

« previous php.dev (#34306) next »