is MAIL safe ?

From: Date: Tue, 14 Dec 2004 21:49:03 +0000
Subject: is MAIL safe ?
Groups: php.pear.general 
Request: Send a blank email to pear-general+get-16244@lists.php.net to get a copy of this message
Hello, I am having users fill out a PDF form with information, having PDF form send FDF data to script on a web sever. Script (see below) takes data file, saves to disk, attaches to email, sends email and then deletes data file from server. All works perfectly. The question: Somebody hacked the server, changing the default.htm pages of each website (domain) to have some spanish political message. The server people are point the blame at me and the PEAR MAIL stuff. This is possible, have I opened the door ? Have looked around for security PEAR MAIL information, but not found any. Surely having the PEAR included with the PHP install points to the fact it is not a risk ? Any information would help me to understand, Thanks Shaun <?php $tmpfname = tempnam("/tmp", "tmp_"); $tmpfname .= ".fdf"; $fptr = fopen("$tmpfname", "w"); fputs($fptr, $HTTP_RAW_POST_DATA); fclose($fptr); ?> <?php include('Mail.php'); include('Mail/mime.php'); $text = '1. Double click the attachment 2. Print the form'; $html = '<html><body><p align="center">1. Double click the attachment2. Print the form</p></body></html>'; $file = $tmpname; $crlf = "\r\n"; $hdrs = array(               'From'    => 'test@testr.info',               'Subject' => 'Form'               ); $mime = new Mail_mime($crlf); $mime->setTXTBody($text); $mime->setHTMLBody($html); $mime->addAttachment($file, 'text/plain'); $body = $mime->get(); $hdrs = $mime->headers($hdrs); $mail =& Mail::factory('mail'); $mail->send('test@test.org', $hdrs, $body); unlink($tmpfname); ?>

« previous php.pear.general (#16244) next »