Req #44187 [Opn->Dup]: mail() function and newlines
| From: | cmb@php.net | Date: | Tue, 13 Mar 2018 16:47:08 +0000 |
| Subject: | Req #44187 [Opn->Dup]: mail() function and newlines | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-214337@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=44187&edit=1
ID: 44187
Updated by: cmb@php.net
Reported by: anzenews at volja dot net
Summary: mail() function and newlines
-Status: Open
+Status: Duplicate
Type: Feature/Change Request
Package: Mail related
Operating System: *
PHP Version: 5.2.5
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Basically, this is a duplicate of bug #68776.
Changing $additional_headers to array would require the RFC
process[1]. Anybody is welcome to start it for this issue.
[1] <https://wiki.php.net/rfc/howto>
Previous Comments:
------------------------------------------------------------------------
[2010-05-19 17:30:04] lukas dot starecek at centrum dot cz
Be careful with that. There have to be newlines in subject if subject is too long (see RFC 2047),
but there must not be two newlines consecutively (two consecutive new lines are header separator).
------------------------------------------------------------------------
[2008-02-20 15:07:11] anzenews at volja dot net
Description:
------------
Most of PHP users are unaware of security implications of such "Send
to friend" scripts:
<?
mail($_POST['send_to_friend'],$_POST['subject'],$_POST['message']);
?>
I propose change of parameters to mail():
mail(array $to, string $subject, string $message[, array
$additional_headers [, string $additional_parameters ]] );
The function should throw a warning if there is a newline anywhere,
even inside arrays, and should not process the mail.
I agree that the programmer should know its tools, BUT:
- the fact is that most of PHP users don't
- most of the TUTORIALS are insecure! A quick search for "PHP mail
example" reveals many prominent pages with such examples.
This is a huge problem and spammers are abusing it extensively.
As this will undoubtedly break some of the scripts (though the fix
should be easy) I suggest adding a configuration statement that
enables such mail() behaviour,
Reproduce code:
---------------
<?
// $POST['send_to_friend'] == "me@example.com\r\n"."
// "BCC: you@example.com";
mail($_POST['send_to_friend'],$_POST['subject'],$_POST['message']);
?>
Expected result:
----------------
Warning: newline in mail() function, line...
Mail not sent or everything after newline ignored.
Actual result:
--------------
Mail sent to me@example.com and to you@example.com.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=44187&edit=1