Doc #54584 [NEW]: Security warning needed
| From: | jstein at image dot dk | Date: | Thu, 21 Apr 2011 08:33:24 +0000 |
| Subject: | Doc #54584 [NEW]: Security warning needed | ||
| Groups: | php.doc.bugs | ||
| Request: | Send a blank email to doc-bugs+get-6270@lists.php.net to get a copy of this message | ||
From:
Operating system:
PHP version: 5.3.6
Package: Security related
Bug Type: Documentation Problem
Bug description:Security warning needed
Description:
------------
---
From manual page: http://www.php.net/reserved.variables.server#Indices
---
The page states that PHP_SELF contains "The filename of the currently
executing script", but it actually contains all of the request path, which
makes it open for HTML injection.
This is by design, but as PHP_SELF is widely used for FORM submission, I
think a security warning would be appropriate.
Test script:
---------------
If a page contains
<form action="<?php echo $_SERVER['PHP_SELF']; ?>">
-and the page is called with:
index.php/"><script>alert('Injection');</script><
The script is injected to the page.
Expected result:
----------------
The behavior is by design - I just think the documentation should contain a
warning on the issue.
--
Edit bug report at http://bugs.php.net/bug.php?id=54584&edit=1
--
Try a snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=54584&r=trysnapshot52
Try a snapshot (PHP 5.3): http://bugs.php.net/fix.php?id=54584&r=trysnapshot53
Try a snapshot (trunk): http://bugs.php.net/fix.php?id=54584&r=trysnapshottrunk
Fixed in SVN: http://bugs.php.net/fix.php?id=54584&r=fixed
Fixed in SVN and need be documented: http://bugs.php.net/fix.php?id=54584&r=needdocs
Fixed in release: http://bugs.php.net/fix.php?id=54584&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=54584&r=needtrace
Need Reproduce Script: http://bugs.php.net/fix.php?id=54584&r=needscript
Try newer version: http://bugs.php.net/fix.php?id=54584&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=54584&r=support
Expected behavior: http://bugs.php.net/fix.php?id=54584&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=54584&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=54584&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=54584&r=globals
PHP 4 support discontinued: http://bugs.php.net/fix.php?id=54584&r=php4
Daylight Savings: http://bugs.php.net/fix.php?id=54584&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=54584&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=54584&r=gnused
Floating point limitations: http://bugs.php.net/fix.php?id=54584&r=float
No Zend Extensions: http://bugs.php.net/fix.php?id=54584&r=nozend
MySQL Configuration Error: http://bugs.php.net/fix.php?id=54584&r=mysqlcfg