Re: Re: #19286 [NEW]: header() Control Char Injection
| From: | Edin Kadribasic | Date: | Sun, 08 Sep 2002 08:27:51 +0000 |
| Subject: | Re: Re: #19286 [NEW]: header() Control Char Injection | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-88061@lists.php.net to get a copy of this message | ||
On Sun, 08 Sep 2002 10:58:24 +0900
Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> This obvious security risk is mentioned in bugtraq today.
>
> IMHO, this is users' fault. They must check values before
> using it. In this specfic case, user should use simple regex
> before feeding str to header().
>
> Any opinion to meke this to "won't fix"?
+1
Validating input is users' resposibility. Besides doing anything about
it would break BC as I've seen several scripts that send 2-3 headers
with one header() call.
Edin