php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #54398 Cannot access security bugs as reporter
Submitted: 2011-03-26 21:41 UTC Modified: 2011-05-06 22:25 UTC
From: lekensteyn at gmail dot com Assigned: bjori (profile)
Status: Closed Package: Website problem
PHP Version: Irrelevant OS: Irrelevant
Private report: No CVE-ID: None
View Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
If you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: lekensteyn at gmail dot com
New email:
PHP Version: OS:

 

 [2011-03-26 21:41 UTC] lekensteyn at gmail dot com
Description:
------------
I've recently reported a few security bugs via this bug tracking system. I have no php.net account, and use the password feature provided by the system.

I can log in, but cannot post comments, nor can I add patches.


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2011-03-26 21:51 UTC] lekensteyn at gmail dot com
Caused by commit 309587:
First step in replacing the auth system...
 - kill MAGIC_COOKIE  <--- argh!
 - update docweb to use the master api
 - update master to use a local session
 - set a IS_DEV cookie, to enable user note editing from phpweb
 - disabled full name retrieval from docweb

http://svn.php.net/viewvc/web/php-bugs/trunk/include/functions.php?r1=309556&r2=309587&sortby=date
 [2011-03-26 22:00 UTC] lekensteyn at gmail dot com
Thanks to Firebug, I injected the following form:
--HTML--
<form action="patch-add.php?bug_id=[private_bug_id]" method="post">
<input type="password" name="pw" />
<input type="submit" />
</form>
--HTML--

After entering the correct password and pressing submit, I get a form on which I can fill the patch details in.
To submit it, I need to add a <input type="password" name="pw" /> field again.

A bit hacky, but it works for me. Note: it should be fixed, why was this "magic cookie" removed?
 [2011-05-06 22:25 UTC] bjori@php.net
-Status: Open +Status: Closed -Assigned To: +Assigned To: bjori
 [2011-05-06 22:25 UTC] bjori@php.net
The magic cookie was removed due to its insane security issues (ironically 
enough, 
by design).


As for your bug report.. This seems to be fixed already.
I filed an bug report with bugtype=security (http://bugs.php.net/bug.php?
id=54679).
Killing the session going and clicking 'edit' and priviting my password I can 
add 
additional comments and all the usual things..

If you can still reproduce this, please provide more details
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sun Oct 11 17:00:01 2026 UTC