From: spam2 at rhsoft dot net Operating system: Linux PHP version: 5.4.13 Package: Scripting Engine problem Bug Type: Bug Bug description:file_get_contents() handles redirects wrong
Description: ------------ [line "182"] [id "950103"] [msg "path traversal attack"] [data "../"] [hostname "test.test.rh"] [uri "/contentlounge/updateservice/cms_demo/cms//../cms.php"] [unique_id "UV2MrQoAAGMAAE356XkAAAAF"] in the folder /cms is a simple index.php with header('Location: ../cms.php'); every normal browser translates path and does not trigger modsec php triggers the "path traversal"-rule Expected result: ---------------- call the URL /contentlounge/updateservice/cms_demo/cms/cms.php Actual result: -------------- calling the URL /contentlounge/updateservice/cms_demo/cms//../cms.php -- Edit bug report at https://bugs.php.net/bug.php?id=64582&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=64582&r=trysnapshot54 Try a snapshot (PHP 5.3): https://bugs.php.net/fix.php?id=64582&r=trysnapshot53 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=64582&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=64582&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=64582&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=64582&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=64582&r=needscript Try newer version: https://bugs.php.net/fix.php?id=64582&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=64582&r=support Expected behavior: https://bugs.php.net/fix.php?id=64582&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=64582&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=64582&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=64582&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=64582&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=64582&r=dst IIS Stability: https://bugs.php.net/fix.php?id=64582&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=64582&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=64582&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=64582&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=64582&r=mysqlcfg