Re: svn: /web/php/trunk/include/ do-download.inc langchooser.inc

From: Date: Fri, 21 Jan 2011 20:38:46 +0000
Subject: Re: svn: /web/php/trunk/include/ do-download.inc langchooser.inc
References: 1 2  Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-10466@lists.php.net to get a copy of this message
Err. No ;) Not *all*, all of the language_add() are bogus.. the first one is quite obvious :P -Hannes On Fri, Jan 21, 2011 at 21:37, Hannes Magnusson <hannes.magnusson@gmail.com> wrote: > Do you have a proof-of-concept or a report or something for these? > They all seem bogus to me.. > > -Hannes > > On Fri, Jan 21, 2011 at 16:28, Rasmus Lerdorf <rasmus@php.net> wrote: >> rasmus                                   Fri, 21 Jan 2011 15:28:33 +0000 >> >> Revision: >> http://svn.php.net/viewvc?view=revision&revision=307654 >> >> Log: >> Fix xss problems >> >> Changed paths: >>    U   web/php/trunk/include/do-download.inc >>    U   web/php/trunk/include/langchooser.inc >> >> Modified: web/php/trunk/include/do-download.inc >> =================================================================== >> --- web/php/trunk/include/do-download.inc       2011-01-21 13:48:25 UTC (rev 307653) >> +++ web/php/trunk/include/do-download.inc       2011-01-21 15:28:33 UTC (rev 307654) >> @@ -32,7 +32,7 @@ >> >>         // If user comes from a mirror selection page, provide a backlink >>         if (isset($_SERVER['HTTP_REFERER']) && >> preg_match("!/from/a/mirror$!", $_SERVER['HTTP_REFERER'])) { >> -            $moreinfo = ", or <a >> href=\"{$_SERVER['HTTP_REFERER']}\">reconsider your mirror >> selection</a>"; >> +            $moreinfo = ", or <a >> href=\"".htmlspecialchars($_SERVER['HTTP_REFERER'],ENT_QUOTES,'UTF-8')."\">reconsider >> your mirror selection</a>"; >>         } else { $moreinfo = ""; } >> >>         // An executable was requested (temp fix for rsync change) >> >> Modified: web/php/trunk/include/langchooser.inc >> =================================================================== >> --- web/php/trunk/include/langchooser.inc       2011-01-21 13:48:25 UTC (rev 307653) >> +++ web/php/trunk/include/langchooser.inc       2011-01-21 15:28:33 UTC (rev 307654) >> @@ -31,7 +31,7 @@ >>  */ >> >>  // Default STRIPPED_URI >> -$_SERVER['STRIPPED_URI'] = $_SERVER['REQUEST_URI']; >> +$_SERVER['STRIPPED_URI'] = htmlspecialchars($_SERVER['REQUEST_URI'], >> ENT_QUOTES, 'UTF-8'); >> >>  // The code is encapsulated in a function, >>  // so the variable namespace is not polluted >> @@ -51,14 +51,14 @@ >> >>     // Specified for the request (GET/POST parameter) >>     if (!empty($_REQUEST['lang'])) { >> -        $explicitly_specified = language_add($_REQUEST['lang'], $languages); >> +        $explicitly_specified = >> language_add(htmlspecialchars($_REQUEST['lang'], ENT_QUOTES, 'UTF-8'), >> $languages); >> >>         // Set the language in a cookie for a year >>         mirror_setcookie("LAST_LANG", $explicitly_specified, 60*60*24*365); >>     } >> >>     // Specified in a shortcut URL (eg. /en/echo or /pt_br/echo) >> -    if (preg_match("!^/(\\w{2}(_\\w{2})?)/!", >> $_SERVER['REQUEST_URI'], $flang)) { >> +    if (preg_match("!^/(\\w{2}(_\\w{2})?)/!", >> htmlspecialchars($_SERVER['REQUEST_URI'],ENT_QUOTES, 'UTF-8'), $flang)) { >> >>         // Put language into preference list >>         $rlang = language_add($flang[1], $languages); >> @@ -70,13 +70,13 @@ >> >>         // Drop out langauge specification from URL, as this is already handled >>         $_SERVER['STRIPPED_URI'] = preg_replace( >> -            "!^/$flang[1]/!", "/", >> $_SERVER['REQUEST_URI'] >> +            "!^/$flang[1]/!", "/", >> htmlspecialchars($_SERVER['REQUEST_URI'], ENT_QUOTES, 'UTF-8') >>         ); >> >>     } >> >>     // Specified in a manual URL (eg. manual/en/ or manual/pt_br/) >> -    if (preg_match("!^/manual/(\\w{2}(_\\w{2})?)(/|$)!", >> $_SERVER['REQUEST_URI'], $flang)) { >> +    if (preg_match("!^/manual/(\\w{2}(_\\w{2})?)(/|$)!", >> htmlspecialchars($_SERVER['REQUEST_URI'], ENT_QUOTES, 'UTF-8'), $flang)) { >> >>         $flang = language_add($flang[1], $languages); >> >> >> >> -- >> PHP Webmaster List Mailing List (http://www.php.net/) >> To unsubscribe, visit: http://www.php.net/unsub.php >> >

« previous php.webmaster (#10466) next »