RE: [PHP-DEV] Re: #19286 [NEW]: header() Control Char Injection

From: Date: Sun, 08 Sep 2002 03:10:47 +0000
Subject: RE: [PHP-DEV] Re: #19286 [NEW]: header() Control Char Injection
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-88059@lists.php.net to get a copy of this message
> Yasuo Ohgaki wrote: > > This obvious security risk is mentioned in bugtraq today. > > > > IMHO, this is users' fault. They must check values before > > using it. In this specfic case, user should use simple regex > > before feeding str to header(). > > > > Any opinion to meke this to "won't fix"? > > One thing we could do is force header parameter a single line. > Any idea it may broke applications? > Don't do that. (seriously, the thing i'm working on right now relies on abusing the http protocol... this is one way i'm doing it...)

« previous php.dev (#88059) next »