php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #2580 Security issue with session IDs
Submitted: 1999-10-20 23:48 UTC Modified: 1999-10-24 12:12 UTC
From: jon at minotaur dot com Assigned:
Status: Closed Package: Misbehaving function
PHP Version: 4.0 Beta 1 OS: Linux 2.0.12
Private report: No CVE-ID: None
View Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
If you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: jon at minotaur dot com
New email:
PHP Version: OS:

 

 [1999-10-20 23:48 UTC] jon at minotaur dot com
There is a problem with PHP4 revision 2 in regards to session IDs.

Turn off cookie mode in your browser.

Change the session temp dir to somewhere else.

When the session ID comes up in your URL, remove the session id, and then add a bunch of ..'s.  For instance, 

http://php.test.com/index.php?SESSIONID=../../../../tmp/test

This will overwrite the file name in that directory called "test".  Though this does not pose a high-risk security problem (due to the fact you'd have to know the file layout) unless of course a doofus has apache running as root.  

I guess Session management may need to be altered so it only accepts md5 hashes as a valid session, bogus things such as ../../.. etc should be removed.

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [1999-10-24 12:12 UTC] sas at cvs dot php dot net
Thanks for the report, we have fixed these issues.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sat Oct 10 11:00:01 2026 UTC