Bug->Doc #81604 [Opn]: Parse_url wrong hostname detection
| From: | cmb@php.net | Date: | Tue, 09 Nov 2021 16:07:58 +0000 |
| Subject: | Bug->Doc #81604 [Opn]: Parse_url wrong hostname detection | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-19323@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81604&edit=1
ID: 81604
Updated by: cmb@php.net
Reported by: noahcore95 at gmail dot com
Summary: Parse_url wrong hostname detection
Status: Open
-Type: Bug
+Type: Documentation Problem
Package: *URL Functions
Operating System: Linux
PHP Version: 7.4.25
Block user comment: N
Private report: N
New Comment:
This is an invalid URI, since the host must not be empty[1].
According to the documentation[2]:
| Partial and invalid URLs are also accepted, parse_url() tries
| its best to parse them correctly.
There is no claim that this best effort matches common browser
behavior. However, the documentation should be improved to make it
clear that at least untrusted input should be checked with
FILTER_VALIDATE_URL, which reports this URI as invalid[3] due to
the fix for bug #81122.
[1] <https://datatracker.ietf.org/doc/html/rfc3986#appendix-A>
[2] <https://www.php.net/parse_url>
[3] <https://3v4l.org/6ed54>
Previous Comments:
------------------------------------------------------------------------
[2021-11-09 13:29:38] noahcore95 at gmail dot com
Description:
------------
Parse_url usage may lead to open redirect vulnerability. Firefox and Chrome opens google.com instead
of php.net.
Test script:
---------------
<?php
$x= 'https://:@google.com\@php.net';
print_r(parse_url($x));
Expected result:
----------------
Array
(
[scheme] => https
[host] => google.com
[user] =>
[pass] => ?
)
Actual result:
--------------
Array
(
[scheme] => https
[host] => php.net
[user] =>
[pass] => @google.com\
)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81604&edit=1