|
php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login |
PatchesPull RequestsHistoryAllCommentsChangesGit/SVN commits
[2011-08-26 22:59 UTC] johannes@php.net
-Status: Open
+Status: Bogus
-Type: Security
+Type: Documentation Problem
[2011-08-26 22:59 UTC] johannes@php.net
[2011-08-26 23:42 UTC] stas@php.net
|
|||||||||||||||||||||||||||
Copyright © 2001-2026 The PHP GroupAll rights reserved. |
Last updated: Thu Oct 08 01:00:01 2026 UTC |
Description: ------------ If you would be writing a framework or any code that the developer can send a parameter though and the receiving code uses is_callable() to test to see if the variable is a lambda/closure type, they may be opening them selves up to a security vulnerability if the attacker is able to set a string to that variable. I recommend adding a note to that function's documentation saying that if you wish to check to see if a variable is a lambda/closure use "is_a($var, 'Closure')". I know this can be avoided by safe coding, but it can be a huge security issue. Test script: --------------- <?php function buildGrid(array $data){ echo '<table>'; foreach($data as $key => $cell){ if(is_callable($cell)){ // This should be is_a($cell, 'Closure') echo $cell($key); }else{ echo '<tr><td>', htmlentities($key), '</td><td>', htmlentities($cell), '</td></tr>'; } } echo '</table>'; } $array = array( 'id' => $_REQUEST['id'], 'name' => $_REQUEST['name'], 'last_name' => $_REQUEST['last_name'], function ($key){ return '<tr><td>A HEADER OR IMAGE OR SOMETHING THAT CANNOT BE EVALUATED OR DISPLAYED UNLESS CALLED AT COMPILE TIME</td></tr>'; } ); buildGrid($array); /* * If the attacker sent a request like: 'index.php?id=11111&name=somename&last_name=phpinfo' * This will show this attacker all the phpinfo() for the server. This could be vary * dangerious if the programmer had a function like showDebugInfo() as the user could possibly * get very valuble info. */ ?>