php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #7256 Different behaviour for 'global $HTTP_POST_VARS; isset($HTTP_POST_VARS)'
Submitted: 2000-10-16 14:34 UTC Modified: 2000-11-03 11:55 UTC
From: hara at oderwat dot de Assigned:
Status: Closed Package: Scripting Engine problem
PHP Version: 4.0.3pl1 OS: Linux SuSE 6.3 - Apache 1.3.9
Private report: No CVE-ID: None
 [2000-10-16 14:34 UTC] hara at oderwat dot de
Hi!

After installing 4.0.3pl1 some of my scripts are broken
because of a different behaviour with the following code:

<?php
function test() {
global $HTTP_POST_VARS;
if(isset($HTTP_POST_VARS)) print "set"; else print "unset";
}
test();
?>

On php-4.0.2 this script prints "unset" (if it was not a post reguest to the server)
on php-4.0.3 the same script always prints "set"

In comparison:

<?php
function test() {
if(isset($GLOBAlS["HTTP_POST_VARS"])) print "set"; else print "unset";
}
test();
?>

works as espected by me...

Was I relaying on some site effekt or is there something
wrong now in 4.0.3pl1

Sincerely,
 Hans Raaf

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2000-11-03 11:32 UTC] hara at oderwat dot de
I still think that this is a problem!
I wonder if anyone can at least answer the question...
 [2000-11-03 11:55 UTC] derick@php.net
It is intended behavior: (As is shown in the bug report update below):

ID: 7611
Updated by: zeev
Reported By: tkruthoff@absolutebackgrounds.com
Status: Closed
Bug Type: Feature/Change Request
Assigned To: 
Comments:

Yes, it is intended (in order to prevent remote users from injecting information into
HTTP_POST_VARS)

 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Fri Oct 09 00:00:01 2026 UTC