Re: [Fwd: PHP fopen() CRLF Injection]

From: Date: Wed, 11 Sep 2002 18:19:29 +0000
Subject: Re: [Fwd: PHP fopen() CRLF Injection]
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-88201@lists.php.net to get a copy of this message
Hi, > We got close one that Jani mentioned in bug db :) > > It's user's problem, but I'm sure there are many > scripts do not check user input enough. > > We're probably better to mention security risks more > in the manual... I fixed this issue in CVS in the way that parse_url() removes control chars from urls when it splits them but infact any url passed to fopen MUST be urlencode()d. Stefan

« previous php.dev (#88201) next »