Bug #81680 [Com]: CR-LF injection via "From" field from ini setting

From: Date: Thu, 28 Sep 2023 09:34:30 +0000
Subject: Bug #81680 [Com]: CR-LF injection via "From" field from ini setting
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-245447@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81680&edit=1

 ID:                 81680
 Comment by:         ta dot nnaowens6 at googlemail dot com
 Reported by:        ive_jihwan at zerocution dot com
 Summary:            CR-LF injection via "From" field from ini setting
 Status:             Verified
 Type:               Bug
 Package:            PHP options/info functions
 Operating System:   *
 PHP Version:        8.1.0
 Block user comment: N
 Private report:     N

 New Comment:

Thanks for sharing this, this is amazing. i like it.
(https://github.com)(https://www.subwaygiftcardbalance.online/)


Previous Comments:
------------------------------------------------------------------------
[2022-12-28 14:04:50] admin at bestcl dot com

Hello friends check out this good references helpful free classified ads usa site
(https://bestclassifiedsusa.com/)github.com

------------------------------------------------------------------------
[2022-12-09 06:01:18] fragomenconnect145 at gmail dot com

Since the injected string can contain CR-LF sequence(\r ), this can be used to interrupt the flow of
FTP stream or injecting/smuggling an outgoing HTTP request.

<https://www.avalon-access.net/>github.com

------------------------------------------------------------------------
[2022-12-07 05:03:05] ramhani14256 at gmail dot com

Yeah, by the reasoning from bug #81518, this is a bug. PHP Copyright © 2001-2022 The PHP Group
All rights reserved.

<https://www.dnahrblock.net/>github.com

------------------------------------------------------------------------
[2021-12-01 10:22:37] cmb@php.net

Yeah, by the reasoning from bug #81518, this is a bug.

------------------------------------------------------------------------
[2021-12-01 02:46:33] ive_jihwan at zerocution dot com

Change a bug package (referred #81518)

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=81680


--
Edit this bug report at https://bugs.php.net/bug.php?id=81680&edit=1


Thread (8 messages)

« previous php.bugs (#245447) next »