php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #54398 Cannot access security bugs as reporter
Submitted: 2011-03-26 21:41 UTC Modified: 2011-05-06 22:25 UTC
From: lekensteyn at gmail dot com Assigned: bjori (profile)
Status: Closed Package: Website problem
PHP Version: Irrelevant OS: Irrelevant
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: lekensteyn at gmail dot com
New email:
PHP Version: OS:

 

 [2011-03-26 21:41 UTC] lekensteyn at gmail dot com
Description:
------------
I've recently reported a few security bugs via this bug tracking system. I have no php.net account, and use the password feature provided by the system.

I can log in, but cannot post comments, nor can I add patches.


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2011-03-26 21:51 UTC] lekensteyn at gmail dot com
Caused by commit 309587:
First step in replacing the auth system...
 - kill MAGIC_COOKIE  <--- argh!
 - update docweb to use the master api
 - update master to use a local session
 - set a IS_DEV cookie, to enable user note editing from phpweb
 - disabled full name retrieval from docweb

http://svn.php.net/viewvc/web/php-bugs/trunk/include/functions.php?r1=309556&r2=309587&sortby=date
 [2011-03-26 22:00 UTC] lekensteyn at gmail dot com
Thanks to Firebug, I injected the following form:
--HTML--
<form action="patch-add.php?bug_id=[private_bug_id]" method="post">
<input type="password" name="pw" />
<input type="submit" />
</form>
--HTML--

After entering the correct password and pressing submit, I get a form on which I can fill the patch details in.
To submit it, I need to add a <input type="password" name="pw" /> field again.

A bit hacky, but it works for me. Note: it should be fixed, why was this "magic cookie" removed?
 [2011-05-06 22:25 UTC] bjori@php.net
-Status: Open +Status: Closed -Assigned To: +Assigned To: bjori
 [2011-05-06 22:25 UTC] bjori@php.net
The magic cookie was removed due to its insane security issues (ironically 
enough, 
by design).


As for your bug report.. This seems to be fixed already.
I filed an bug report with bugtype=security (http://bugs.php.net/bug.php?
id=54679).
Killing the session going and clicking 'edit' and priviting my password I can 
add 
additional comments and all the usual things..

If you can still reproduce this, please provide more details
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sun Oct 11 18:00:01 2026 UTC