Bug #81680 [Com]: CR-LF injection via "From" field from ini setting
Edit report at https://bugs.php.net/bug.php?id=81680&edit=1
ID: 81680
Comment by: ta dot nnaowens6 at googlemail dot com
Reported by: ive_jihwan at zerocution dot com
Summary: CR-LF injection via "From" field from ini setting
Status: Verified
Type: Bug
Package: PHP options/info functions
Operating System: *
PHP Version: 8.1.0
Block user comment: N
Private report: N
New Comment:
Thanks for sharing this, this is amazing. i like it.
(https://github.com)(https://www.subwaygiftcardbalance.online/)
Previous Comments:
------------------------------------------------------------------------
[2022-12-28 14:04:50] admin at bestcl dot com
Hello friends check out this good references helpful free classified ads usa site
(https://bestclassifiedsusa.com/)github.com
------------------------------------------------------------------------
[2022-12-09 06:01:18] fragomenconnect145 at gmail dot com
Since the injected string can contain CR-LF sequence(\r ), this can be used to interrupt the flow of
FTP stream or injecting/smuggling an outgoing HTTP request.
<https://www.avalon-access.net/>github.com
------------------------------------------------------------------------
[2022-12-07 05:03:05] ramhani14256 at gmail dot com
Yeah, by the reasoning from bug #81518, this is a bug. PHP Copyright © 2001-2022 The PHP Group
All rights reserved.
<https://www.dnahrblock.net/>github.com
------------------------------------------------------------------------
[2021-12-01 10:22:37] cmb@php.net
Yeah, by the reasoning from bug #81518, this is a bug.
------------------------------------------------------------------------
[2021-12-01 02:46:33] ive_jihwan at zerocution dot com
Change a bug package (referred #81518)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=81680
--
Edit this bug report at https://bugs.php.net/bug.php?id=81680&edit=1
Thread (8 messages)