php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #2580 Security issue with session IDs
Submitted: 1999-10-20 23:48 UTC Modified: 1999-10-24 12:12 UTC
From: jon at minotaur dot com Assigned:
Status: Closed Package: Misbehaving function
PHP Version: 4.0 Beta 1 OS: Linux 2.0.12
Private report: No CVE-ID: None
 [1999-10-20 23:48 UTC] jon at minotaur dot com
There is a problem with PHP4 revision 2 in regards to session IDs.

Turn off cookie mode in your browser.

Change the session temp dir to somewhere else.

When the session ID comes up in your URL, remove the session id, and then add a bunch of ..'s.  For instance, 

http://php.test.com/index.php?SESSIONID=../../../../tmp/test

This will overwrite the file name in that directory called "test".  Though this does not pose a high-risk security problem (due to the fact you'd have to know the file layout) unless of course a doofus has apache running as root.  

I guess Session management may need to be altered so it only accepts md5 hashes as a valid session, bogus things such as ../../.. etc should be removed.

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [1999-10-24 12:12 UTC] sas at cvs dot php dot net
Thanks for the report, we have fixed these issues.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sat Oct 10 11:00:01 2026 UTC