Re: [Fwd: PHP fopen() CRLF Injection]
| From: | Stefan Esser | Date: | Wed, 11 Sep 2002 18:19:29 +0000 |
| Subject: | Re: [Fwd: PHP fopen() CRLF Injection] | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-88201@lists.php.net to get a copy of this message | ||
Hi,
> We got close one that Jani mentioned in bug db :)
>
> It's user's problem, but I'm sure there are many
> scripts do not check user input enough.
>
> We're probably better to mention security risks more
> in the manual...
I fixed this issue in CVS in the way that parse_url() removes
control chars from urls when it splits them but infact any url
passed to fopen MUST be urlencode()d.
Stefan