#19120 [NEW]: Open-relay PHP script using unfiltered data on mail()
| From: | vogel at folz dot de | Date: | Tue, 27 Aug 2002 09:27:52 +0000 |
| Subject: | #19120 [NEW]: Open-relay PHP script using unfiltered data on mail() | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-17922@lists.php.net to get a copy of this message | ||
From: vogel@folz.de
Operating system: Linux (or any Unix)
PHP version: 4.2.2
PHP Bug Type: Mail related
Bug description: Open-relay PHP script using unfiltered data on mail()
Well, I'm not the person who found this, I just
want to have this reported here.
A few days ago Wojciech Purczynski <cliph@isec.pl>
reported a security problem with the mail()
function to bugtraq, see:
http://online.securityfocus.com/archive/1/288804
I must admit that I haven't checked the validity
of his claims. But because there is still no
reply from anyone to his email on bugtraq, I figured
it should be reported here.
--
Edit bug report at http://bugs.php.net/?id=19120&edit=1
--
Try a CVS snapshot: http://bugs.php.net/fix.php?id=19120&r=trysnapshot
Fixed in CVS: http://bugs.php.net/fix.php?id=19120&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=19120&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=19120&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=19120&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=19120&r=support
Expected behavior: http://bugs.php.net/fix.php?id=19120&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=19120&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=19120&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=19120&r=globals