Re: Re: #19286 [NEW]: header() Control Char Injection

From: Date: Sun, 08 Sep 2002 12:04:28 +0000
Subject: Re: Re: #19286 [NEW]: header() Control Char Injection
References: 1 2 3  Groups: php.dev 
Request: Send a blank email to php-dev+get-88068@lists.php.net to get a copy of this message
Morning, I wonder when we will see: PHP include() PHP Code Injection on Bugtraq ;) [X] Injecting HTTP headers is indeed possible with his technique. [X] -> You can inject Cookies... [X] Injecting Part of the Body is possible, too. [X] Browsers ignore anything in the Body when "Location" is used. [ ] His Java Script will be executed. Stefan Esser PS: Is php-dev censored? Or why disappeared my mail about MD5/GPG signs of PHP 4.2.3... Is there some autofilter on "group says everytime: we do it the next time?"

« previous php.dev (#88068) next »