Doc #54584 [Opn->Bgs]: Security warning needed

From: Date: Thu, 21 Apr 2011 19:15:35 +0000
Subject: Doc #54584 [Opn->Bgs]: Security warning needed
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-6272@lists.php.net to get a copy of this message
Edit report at http://bugs.php.net/bug.php?id=54584&edit=1 ID: 54584 Updated by: dtajchreber@php.net Reported by: jstein at image dot dk Summary: Security warning needed -Status: Open +Status: Bogus Type: Documentation Problem Package: Security related PHP Version: 5.3.6 Block user comment: N Private report: N New Comment: We don't have security warnings for $_GET, $_POST, or $_COOKIE... or any pages that I can find. I don't think adding one to this page is all that crucial. Previous Comments: ------------------------------------------------------------------------ [2011-04-21 10:33:22] jstein at image dot dk Description: ------------ --- From manual page: http://www.php.net/reserved.variables.server#Indices --- The page states that PHP_SELF contains "The filename of the currently executing script", but it actually contains all of the request path, which makes it open for HTML injection. This is by design, but as PHP_SELF is widely used for FORM submission, I think a security warning would be appropriate. Test script: --------------- If a page contains <form action="<?php echo $_SERVER['PHP_SELF']; ?>"> -and the page is called with: index.php/"><script>alert('Injection');</script>< The script is injected to the page. Expected result: ---------------- The behavior is by design - I just think the documentation should contain a warning on the issue. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/bug.php?id=54584&edit=1

« previous php.doc.bugs (#6272) next »