Doc #54584 [Com]: Security warning needed
| From: | tyra3l at gmail dot com | Date: | Thu, 21 Apr 2011 19:43:29 +0000 |
| Subject: | Doc #54584 [Com]: Security warning needed | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-6273@lists.php.net to get a copy of this message | ||
Edit report at http://bugs.php.net/bug.php?id=54584&edit=1
ID: 54584
Comment by: tyra3l at gmail dot com
Reported by: jstein at image dot dk
Summary: Security warning needed
Status: Bogus
Type: Documentation Problem
Package: Security related
PHP Version: 5.3.6
Block user comment: N
Private report: N
New Comment:
I disagree with you.
it's common knowledge that using $_GET, $_POST etc. without properly
sanitazing
first is dangerous.
but the XSS vulnerability about PHP_SELF is not that well-known.
at least for the average developers.
Tyrael
Previous Comments:
------------------------------------------------------------------------
[2011-04-21 21:15:34] dtajchreber@php.net
We don't have security warnings for $_GET, $_POST, or $_COOKIE... or any
pages
that I can find. I don't think adding one to this page is all that
crucial.
------------------------------------------------------------------------
[2011-04-21 10:33:22] jstein at image dot dk
Description:
------------
---
From manual page: http://www.php.net/reserved.variables.server#Indices
---
The page states that PHP_SELF contains "The filename of the currently
executing script", but it actually contains all of the request path,
which makes it open for HTML injection.
This is by design, but as PHP_SELF is widely used for FORM submission, I
think a security warning would be appropriate.
Test script:
---------------
If a page contains
<form action="<?php echo $_SERVER['PHP_SELF']; ?>">
-and the page is called with:
index.php/"><script>alert('Injection');</script><
The script is injected to the page.
Expected result:
----------------
The behavior is by design - I just think the documentation should
contain a warning on the issue.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/bug.php?id=54584&edit=1