Re: Re: #19286 [NEW]: header() Control Char Injection

From: Date: Sun, 08 Sep 2002 08:27:51 +0000
Subject: Re: Re: #19286 [NEW]: header() Control Char Injection
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-88061@lists.php.net to get a copy of this message
On Sun, 08 Sep 2002 10:58:24 +0900 Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > This obvious security risk is mentioned in bugtraq today. > > IMHO, this is users' fault. They must check values before > using it. In this specfic case, user should use simple regex > before feeding str to header(). > > Any opinion to meke this to "won't fix"? +1 Validating input is users' resposibility. Besides doing anything about it would break BC as I've seen several scripts that send 2-3 headers with one header() call. Edin

« previous php.dev (#88061) next »