Bug #12178 Updated: ext/standard/mail.c insecurity
| From: | derick@php.net | Date: | Fri, 30 Nov 2001 09:26:07 +0000 |
| Subject: | Bug #12178 Updated: ext/standard/mail.c insecurity | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-72110@lists.php.net to get a copy of this message | ||
ID: 12178
Updated by: derick
Reported By: sintes@nfrance.com
Old Status: Open
Status: Closed
Bug Type: Mail related
Operating System: All UNIX
PHP Version: 4.0.6
New Comment:
This was fixed a long time ago. (on 2001/07/05 08:47:37)
Previous Comments:
------------------------------------------------------------------------
[2001-07-15 13:14:46] sintes@nfrance.com
ext/standard/mail.c is potentialy insecure.
>extra_cmd = (*argv[4])->value.str.val;
>strcat (sendmail_cmd, extra_cmd);
>sendmail = popen(sendmail_cmd, "w");
So it is possible to use extra_cmd to gain shell access.
------------------------------------------------------------------------
Edit this bug report at http://bugs.php.net/?id=12178&edit=1