Re: [Fwd: PHP fopen() CRLF Injection]
| From: | Stefan Esser | Date: | Thu, 12 Sep 2002 09:56:08 +0000 |
| Subject: | Re: [Fwd: PHP fopen() CRLF Injection] | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-88244@lists.php.net to get a copy of this message | ||
On Thu, Sep 12, 2002 at 10:47:12AM +0100, James Cox wrote:
> Stefan,
>
> is this really worth it? I think this will break too many scripts.
>
> -- james
My change only changes parse_url() to remove characters that
are invalid in urls. If such characters occur in an url that
is passed to parse_url() this is "DANGEROUS". And using such
an url makes no sense cause whereever you store it and reread
it is simply an invalid url. So if any script fails because
of my change it is a bug in the script. (i cannot imagine a
legal use of control characters in urls in any script ...)
Stefan