Bug #12268 Updated: Security bug in php 4.0.5+

From: Date: Fri, 20 Jul 2001 00:56:28 +0000
Subject: Bug #12268 Updated: Security bug in php 4.0.5+
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-60345@lists.php.net to get a copy of this message
ID: 12268 Updated by: rasmus Reported By: hard.disk@uol.com.br Old Status: Open Status: Closed Bug Type: *Mail Related Operating System: Any PHP Version: 4.0.5 New Comment: Fixed a while ago in CVS Previous Comments: ------------------------------------------------------------------------ [2001-07-19 19:29:34] hard.disk@uol.com.br http://www.net-security.org/text/bugs/995534103,28541,.shtml: PHP Mail Function Vulnerability Posted on 19.7.2001 php mail() function does not do check for escape shell commandes, even if php is running in safe_mode. So it's may be possible to bypass the safe_mode restriction and gain shell access. Affected: php4.0.6 php4.0.5 Significatives lines of ext/standard/mail.c: >extra_cmd = (*argv[4])->value.str.val; >strcat (sendmail_cmd, extra_cmd); >sendmail = popen(sendmail_cmd, "w"); Exploit: mail("toto@toto.com", "test", "test", "test", "; shell_cmd"); ------------------------------------------------------------------------ Edit this bug report at http://bugs.php.net/?id=12268&edit=1

« previous php.dev (#60345) next »