php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #55516 is_callable can be a security vulnerability
Submitted: 2011-08-26 22:25 UTC Modified: 2011-08-26 23:42 UTC
From: thegreatall at gmail dot com Assigned:
Status: Not a bug Package: Documentation problem
PHP Version: Irrelevant OS: N/A
Private report: No CVE-ID: None
 [2011-08-26 22:25 UTC] thegreatall at gmail dot com
Description:
------------
If you would be writing a framework or any code that the developer can send a 
parameter though and the receiving code uses is_callable() to test to see if the 
variable is a lambda/closure type, they may be opening them selves up to a 
security vulnerability if the attacker is able to set a string to that variable. I 
recommend adding a note to that function's documentation saying that if you wish 
to check to see if a variable is a lambda/closure use "is_a($var, 'Closure')". I 
know this can be avoided by safe coding, but it can be a huge security issue.

Test script:
---------------
<?php
function buildGrid(array $data){
	echo '<table>';
	foreach($data as $key => $cell){
		if(is_callable($cell)){ // This should be is_a($cell, 'Closure')
			echo $cell($key);
		}else{
			echo '<tr><td>', htmlentities($key), '</td><td>', htmlentities($cell), '</td></tr>';
		}
	}
	echo '</table>';
}

$array = array(
	'id' => $_REQUEST['id'],
	'name' => $_REQUEST['name'],
	'last_name' => $_REQUEST['last_name'],
	function ($key){
		return '<tr><td>A HEADER OR IMAGE OR SOMETHING THAT CANNOT BE EVALUATED OR DISPLAYED UNLESS CALLED AT COMPILE TIME</td></tr>';
	}
);
buildGrid($array);
/*
 * If the attacker sent a request like: 'index.php?id=11111&name=somename&last_name=phpinfo'
 * This will show this attacker all the phpinfo() for the server. This could be vary
 * dangerious if the programmer had a function like showDebugInfo() as the user could possibly
 * get very valuble info.
 */
?>


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2011-08-26 22:59 UTC] johannes@php.net
-Status: Open +Status: Bogus -Type: Security +Type: Documentation Problem
 [2011-08-26 22:59 UTC] johannes@php.net
It is documented, that strings are callable types. We can't prevent all the ways a PHP developer can shoot in his foot.
 [2011-08-26 23:42 UTC] stas@php.net
Also, you should use "$var instanceof Closure" in this case :)
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Thu Oct 08 02:00:01 2026 UTC