From: Stefan Esser Date: Sat, 16 Jun 2007 07:48:07 +0000 (+0000) Subject: MFH X-Git-Tag: php-5.2.4RC1~339 X-Git-Url: https://granicus.if.org/sourcecode?a=commitdiff_plain;h=df7bfe0a0f3175e8d4573a2e9501cf11e2c0bee3;p=php MFH --- diff --git a/ext/session/session.c b/ext/session/session.c index 3d87a423c5..51e63171e5 100644 --- a/ext/session/session.c +++ b/ext/session/session.c @@ -807,7 +807,7 @@ static void php_session_initialize(TSRMLS_D) int vallen; /* check session name for invalid characters */ - if (PS(id) && strpbrk(PS(id), "\r\n\t <>'\"\\()@,;:[]?={}&%")) { + if (PS(id) && strpbrk(PS(id), "\r\n\t <>'\"\\")) { efree(PS(id)); PS(id) = NULL; } @@ -1080,6 +1080,7 @@ static void php_session_send_cookie(TSRMLS_D) { smart_str ncookie = {0}; char *date_fmt = NULL; + char *e_session_name, *e_id; if (SG(headers_sent)) { char *output_start_filename = php_get_output_start_filename(TSRMLS_C); @@ -1093,11 +1094,18 @@ static void php_session_send_cookie(TSRMLS_D) } return; } + + /* URL encode session_name and id because they might be user supplied */ + e_session_name = php_url_encode(PS(session_name), strlen(PS(session_name)), NULL); + e_id = php_url_encode(PS(id), strlen(PS(id)), NULL); smart_str_appends(&ncookie, COOKIE_SET_COOKIE); - smart_str_appends(&ncookie, PS(session_name)); + smart_str_appends(&ncookie, e_session_name); smart_str_appendc(&ncookie, '='); - smart_str_appends(&ncookie, PS(id)); + smart_str_appends(&ncookie, e_id); + + efree(e_session_name); + efree(e_id); if (PS(cookie_lifetime) > 0) { struct timeval tv;