Bug #13645: variables_order influences HTTP_*_VARS
| From: | hp at oeri dot ch | Date: | Thu, 11 Oct 2001 22:10:00 +0000 |
| Subject: | Bug #13645: variables_order influences HTTP_*_VARS | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-67806@lists.php.net to get a copy of this message | ||
From: hp@oeri.ch
Operating system: Mandrake Linux 8.0
PHP version: 4.0.6
PHP Bug Type: *Configuration Issues
Bug description: variables_order influences HTTP_*_VARS
As for the logic of the php.ini texts, I understand variables_order defines
the order in which vars are assigned into global space. track_vars should
enable ALL HTTP_*_VARS.
However, leaving out one of egpcs in variables_order disables the
corresponding HTTP_*_VARS! (empty array)
Besides the point, that this seems to be not-as-documented, "correct"
behaviour would solve a whole lot of security problems:
; only assign "safe" variables to global space, but DO
; assign them -> convenience for safe vars!
variables_order = "S"
; access all other by HTTP_*_VARS
track_vars = on
Please correct me, if I'm wrong.
--
Edit bug report at: http://bugs.php.net/?id=13645&edit=1