PHP 4.0 Bug #7044 Updated: Session file created when using bogus SESSIONID
| From: | sas@php.net | Date: | Mon, 16 Oct 2000 18:18:26 +0000 |
| Subject: | PHP 4.0 Bug #7044 Updated: Session file created when using bogus SESSIONID | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-35173@lists.php.net to get a copy of this message | ||
ID: 7044
Updated by: sas
Reported By: kimmel@tricos.com
Status: Closed
Bug Type: *Session related
Assigned To:
Comments:
That is comparable to having many visitors to your site.
Previous Comments:
---------------------------------------------------------------------------
[2000-10-05 20:20:53] kimmel@tricos.com
JFYI: I'm using IIS/PWS (SP5) with the PHP CGI version.
---------------------------------------------------------------------------
[2000-10-05 19:28:29] kimmel@tricos.com
JFYI: I'm using IIS/PWS (SP5) with the PHP CGI version.
---------------------------------------------------------------------------
[2000-10-05 17:27:27] kimmel@tricos.com
I'm using the <?=SID?> feature to automatically append the corresponding session ID to
every link, so that no cookies are required to use the site.
A sample URL as visible on the browser´s address bar:
http://webtest/human_resources.phtml?SESSIONID=cca7f03abde2c33077df25999850d6dc
Now if I change the SESSIONID parameter to something really stupid PHP simply creates a file with
exactly that name regardless if a session with that SESSIONID has never been created before by
session_start():
http://webtest/human_resources.phtml?SESSIONID=stupidsessionid
creates the file "sessstupidsessionid" in the session directory.
Why?
This way someone could fill up the whole directory!
---------------------------------------------------------------------------
Full Bug description available at: http://bugs.php.net/?id=7044