Re: HTTP Response Splitting
| From: | Sascha Schumann | Date: | Tue, 12 Oct 2004 05:40:38 +0000 |
| Subject: | Re: HTTP Response Splitting | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-13272@lists.php.net to get a copy of this message | ||
On Mon, 11 Oct 2004, Andi Gutmans wrote:
> I think you are right. The only problem I can see is that people added more
> than one header with a header() call and it actually having worked under some
> SAPIs. My guess is that this has happened quite often and it might break quite
> a few apps.
In contrast to other bad programming habbits, I have not seen
this in actual code anywhere so far.
Are there any examples of real applications doing this?
We could start emitting a warning by default:
cleanup_header = false
cleanup_header_warning = true
And later change the default of cleanup_header to true.
- Sascha