PHP 4.0 Bug #7987 Updated: POST/GET: string with NULL values not parsed correctly
| From: | stas@php.net | Date: | Tue, 12 Dec 2000 10:53:58 +0000 |
| Subject: | PHP 4.0 Bug #7987 Updated: POST/GET: string with NULL values not parsed correctly | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-40944@lists.php.net to get a copy of this message | ||
ID: 7987
Updated by: stas
Reported By: andbe611@student.liu.se
Old-Status: Open
Status: Closed
Bug Type: HTTP related
Assigned To:
Comments:
Fixed in CVS.
Previous Comments:
---------------------------------------------------------------------------
[2000-11-28 09:24:39] andbe611@student.liu.se
Ok, I found this in:
php_variables.c row 202
/* FIXME: XXX: not binary safe, discards returned length */
php_url_decode(var, strlen(var));
php_url_decode(val, strlen(val));
php_register_variable(var, val, array_ptr ELS_CC PLS_CC);
So I guess you are already aware of the problem.
---------------------------------------------------------------------------
[2000-11-27 11:38:43] andbe611@student.liu.se
Here is a short script that shows the problem. (I guess I should have posted thins in my first
bugreport, sorry)
The script null_string.php gets called with:
http://myserver.com/null_string.php?truncated=hello%00world
null_string.php:
<?php
$works= "hellox00world";
$fp = fopen("file.txt","w");
fwrite($fp,"$worksn");
fwrite($fp,"$truncatedn");
fclose($fp);
?>
file.txt opened in an hex editor:
hex: 68 65 6C 6C 6F 00 77 6F-72 6C 64 0A 68 65 6C 6C 6F 0A
text:hello.world.hello.
The $works is saved with the null value, but the $truncated in the get request gets truncated by
php.
---------------------------------------------------------------------------
[2000-11-27 06:34:58] waldschrott@php.net
maybe duplicate of 7621
---------------------------------------------------------------------------
[2000-11-27 06:28:26] waldschrott@php.net
are you sure they get truncated?
please echo strlen($HTTP_POST_VARS["var"]) *before* the
other output and please don't use NS 4.x it is known to
truncate an unknown number of bytes after a