Skip to content

maximum length not enforced in cgi.parse() #42628

Description

@adr26
mannequin
BPO 1367631

Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

Show more details

GitHub fields:

assignee = None
closed_at = None
created_at = <Date 2005-11-27.17:47:58.000>
labels = ['type-bug', 'library']
title = 'maximum length not enforced in cgi.parse()'
updated_at = <Date 2014-02-03.19:54:39.486>
user = 'https://bugs.python.org/adr26'

bugs.python.org fields:

activity = <Date 2014-02-03.19:54:39.486>
actor = 'BreamoreBoy'
assignee = 'none'
closed = False
closed_date = None
closer = None
components = ['Library (Lib)']
creation = <Date 2005-11-27.17:47:58.000>
creator = 'adr26'
dependencies = []
files = []
hgrepos = []
issue_num = 1367631
keywords = []
message_count = 3.0
messages = ['26928', '109880', '115231']
nosy_count = 1.0
nosy_names = ['adr26']
pr_nums = []
priority = 'normal'
resolution = 'wont fix'
stage = 'test needed'
status = 'languishing'
superseder = None
type = 'behavior'
url = 'https://bugs.python.org/issue1367631'
versions = ['Python 3.1', 'Python 2.7', 'Python 3.2']

Activity

  1. adr26 commented on Nov 27, 2005

    adr26mannequin
    MannequinAuthor

    I have a simple form in HTML to upload a file:

    <form action="http://foo/cgi-bin/test.py"
    enctype="multipart/form-data" method="post">
    <p>
    Please specify a file:<br>
    <input type="file" name="file_1" size="40">
    </p>
    <p>
    <input type="submit" value="Send">
    </p>
    </form>

    I use this to post to a CGI python script that looks
    like this:

    import cgi
    import cgitb; cgitb.enable()
    
    cgi.maxlen = 50

    print "Content-type: text/plain"
    print

    q = cgi.parse()
    print q

    I was expecting that cgi.pm would then throw an
    exception if I send a file > 50 bytes long to it. If
    I construct a FieldStorage object, it certainly
    does:

    form = cgi.FieldStorage()
    print form

    The issue is that in parse_multipart() in cgi.pm, if
    a part of a multi-part message does not have the
    Content-Length header, you read lines until you
    get to the next boundary "--...", but don't honour
    maxlen whilst doing so. I'd consider this to be a bug
    and would even be happy to have a go at fixing
    it as my first contribution to Python, should others
    concur with me... :-)

  2. added
    stdlibStandard Library Python modules in the Lib/ directory
    on Nov 27, 2005
  3. BreamoreBoy commented on Jul 10, 2010

    BreamoreBoymannequin
    Mannequin

    Andrew could you please provide a patch.

  4. BreamoreBoy commented on Aug 30, 2010

    BreamoreBoymannequin
    Mannequin

    No reply to msg109880.

  5. added
    staleStale PR or inactive for long period of time.
    on Aug 31, 2010
  6. added
    staleStale PR or inactive for long period of time.
    on Aug 31, 2010
  7. transferred this issue fromon Apr 10, 2022
  8. hugovk commented on Apr 11, 2022

    @hugovk
    Member

    Let's close this old issue, the cgi module is deprecated in 3.11 and set for removal in 3.13.

    See PEP 594 – Removing dead batteries from the standard library, #91217 and #32410.

    There's a fork at https://pypi.org/project/legacy-cgi/.

  9. AlexWaygood commented on Apr 12, 2022

    @AlexWaygood
    Member

    Let's close this old issue, the cgi module is deprecated in 3.11 and set for removal in 3.13.

    See PEP 594 – Removing dead batteries from the standard library, #91217 and #32410.

    There's a fork at https://pypi.org/project/legacy-cgi/.

    Cc. @adr26

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    stdlibStandard Library Python modules in the Lib/ directorytype-bugAn unexpected behavior, bug, or error

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions