#29151 [Opn]: bugs.php.net fails to insert vote
| From: | dave@php.net | Date: | Tue, 20 Jul 2004 05:23:49 +0000 |
| Subject: | #29151 [Opn]: bugs.php.net fails to insert vote | ||
| References: | 1 | Groups: | php.mirrors |
| Request: | Send a blank email to php-mirrors+get-25424@lists.php.net to get a copy of this message | ||
ID: 29151
Updated by: dave@php.net
Reported By: fdsoft at pganet dot com
Status: Open
Bug Type: Website problem
Operating System: irrelevant
PHP Version: Irrelevant
New Comment:
The offending code would be:
$ip = ip2long($HTTP_X_FORWARDED_FOR ? $HTTP_X_FORWARDED_FOR :
$REMOTE_ADDR);
Normally a single proxy sits between the client and the server, giving
a single IP address that ip2long() accepts, but if a connection is
bounced through a chain of proxies, the X-Forwarded-For header will
contain a list of those IPs in the form of: "X-Forwarded-For: <ip>[,
<ip2>, ...]". eg. "X-Forwarded-For: 10.0.0.1, 10.0.0.2". This is
probably why ip2long() is failing for these two people.
Also, if you're not using a proxy that sets X-Forwarded-For, any client
can set this header, making it untrustworthy. I could set my
X-Forwarded-For: header to 'BLAH' and this script would fail.
I suggest someone with php-bugs-web karma simply remove the
X-Forwarded-For part and change the offending line to:
$ip = ip2long($REMOTE_ADDR);
If it becomes a problem with multiple people behind the same proxy,
then you can add in exceptions for those people as the issue arises.
Previous Comments:
------------------------------------------------------------------------
[2004-07-20 06:49:24] mike at psy dot otago dot ac dot nz
I'd like to vote on this as well instead of having to 'Me too!' but I
can't vote :-)
query INSERT INTO bugdb_votes
(bug,ip,score,reproduced,tried,sameos,samever)
VALUES(20720,,1,1,1,0,0); failed: You have an error in your SQL syntax.
Check the manual that corresponds to your MySQL server version for the
right syntax to use near '1,1,1,0,0)' at line 1
------------------------------------------------------------------------
[2004-07-14 15:55:14] fdsoft at pganet dot com
Description:
------------
Trying to vote on a bug resulted in the following page:
query INSERT INTO bugdb_votes
(bug,ip,score,reproduced,tried,sameos,samever)
VALUES(29149,,-2,1,1,0,0); failed: You have an error in
your SQL syntax. Check the manual that corresponds to
your MySQL server version for the right syntax to use
near '-2,1,1,0,0)' at line 1
I suspect the website code is trying to use
$_SERVER["HTTP_X_FORWARDED_FOR"] which is set to the
string "unknown" in my case, a common configuration
option for the Squid web proxy.
$_SERVER["REMOTE_ADDR"] would contain the correct IP
address of my proxy.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=29151&edit=1