#19120 [NEW]: Open-relay PHP script using unfiltered data on mail()

From: Date: Tue, 27 Aug 2002 09:27:52 +0000
Subject: #19120 [NEW]: Open-relay PHP script using unfiltered data on mail()
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-17922@lists.php.net to get a copy of this message
From: vogel@folz.de Operating system: Linux (or any Unix) PHP version: 4.2.2 PHP Bug Type: Mail related Bug description: Open-relay PHP script using unfiltered data on mail() Well, I'm not the person who found this, I just want to have this reported here. A few days ago Wojciech Purczynski <cliph@isec.pl> reported a security problem with the mail() function to bugtraq, see: http://online.securityfocus.com/archive/1/288804 I must admit that I haven't checked the validity of his claims. But because there is still no reply from anyone to his email on bugtraq, I figured it should be reported here. -- Edit bug report at http://bugs.php.net/?id=19120&edit=1 -- Try a CVS snapshot: http://bugs.php.net/fix.php?id=19120&r=trysnapshot Fixed in CVS: http://bugs.php.net/fix.php?id=19120&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=19120&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=19120&r=needtrace Try newer version: http://bugs.php.net/fix.php?id=19120&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=19120&r=support Expected behavior: http://bugs.php.net/fix.php?id=19120&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=19120&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=19120&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=19120&r=globals

« previous php.bugs (#17922) next »