|
php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login |
[2021-09-19 22:51 UTC] ddpm at liscovius dot de
Description: ------------ Just trying if a bug appears also on live system. Triggered it on my dev environment. Test script: --------------- will do github PR if verified. PatchesPull RequestsHistoryAllCommentsChangesGit/SVN commits
|
|||||||||||||||||||||||||||
Copyright © 2001-2025 The PHP GroupAll rights reserved. |
Last updated: Sun Oct 26 08:00:02 2025 UTC |
You might change the title to 'better validation of input parameters of report.php' or something like that. I got full path with PHP8 when I change the in[passwd] to in[passwd][ooops] in the report.php form as POST parameter in[passwd] Better add is_string() or similiar check before passing to hash_hmac(). Fatal error: Uncaught TypeError: hash_hmac(): Argument #2 ($data) must be of type string, array given in /var/www/html/bugs/include/functions.php:1692 Stack trace: #0 /var/www/html/bugs/include/functions.php(1692): hash_hmac() #1 /var/www/html/bugs/www/report.php(224): bugs_get_hash() #2 {main} thrown in /var/www/html/bugs/include/functions.php on line 1692 Also spits 'Warning: Undefined array key "package_name" in /var/www/html/bugs/www/report.php on line 70' when I submit form without selecting a package_name on local dev engine with PHP8.0.10