Doc #64069 [Opn]: Function strcasecmp will return NULL if it gets an array.

From: Date: Fri, 25 Jan 2013 09:18:33 +0000
Subject: Doc #64069 [Opn]: Function strcasecmp will return NULL if it gets an array.
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-9475@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64069&edit=1

 ID:                 64069
 User updated by:    cayce245 at gmail dot com
 Reported by:        cayce245 at gmail dot com
 Summary:            Function strcasecmp will return NULL if it gets an
                     array.
 Status:             Open
 Type:               Documentation Problem
 Package:            Documentation problem
 PHP Version:        Irrelevant
 Block user comment: N
 Private report:     N

 New Comment:

Query /?pass[] will authorize user **


Previous Comments:
------------------------------------------------------------------------
[2013-01-25 08:55:24] cayce245 at gmail dot com

Description:
------------
---
From manual page: http://www.php.net/function.strcasecmp#refsect1-
function.strcasecmp-returnvalues
---

Function strcasecmp will return NULL if it gets an array. Now it seems that 
function will return only an integer, and this 
assumption can be a security risk, like in the example bellow.

Test script:
---------------
<?php
$pass = isset($_GET['pass'])?$_GET['pass']:'';

    // Query /?pass=[] will authorize user
if ( strcasecmp( $pass, '123456' ) == 0 )
{
  echo 'You successfully logged in.';
}



------------------------------------------------------------------------



-- 
Edit this bug report at https://bugs.php.net/bug.php?id=64069&edit=1


Thread (3 messages)

« previous php.doc.bugs (#9475) next »