PHP mail() Function Lets Remote Users Inject E-mail Headers
|
|
SecurityTracker Alert ID: 1017946
|
|
SecurityTracker URL: http://securitytracker.com/id?1017946
|
|
CVE Reference: CVE-2007-1718
(Links to External Site)
|
Updated: May 5 2007
|
Original Entry Date: Apr 20 2007
|
Impact: Host/resource access via network
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Version(s): 4.4.6 and prior 4.x versions, 5.2.1 and prior 5.x versions
|
Description: A vulnerability was reported in PHP in the mail() function. A remote user can inject e-mail headers
The mail() function does not properly process folded mail headers. A remote user can exploit this to inject e-mail headers into
the 'To' and 'Subject' parameters.
Stefan Esser discovered this vulnerability.
The original advisory is available at:
http://www.php-security.org/MOPB/MOPB-34-20
07.html
|
Impact: A remote user can inject e-mail headers.
|
Solution: The vendor has issued a fixed version (5.2.2).
The PHP advisory is available at:
http://www.php.net/releases/5_2_2.php
|
Vendor URL: www.php.net/ (Links to External Site)
|
Cause: Input validation error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Fri, 20 Apr 2007 08:43:57 -0400
Subject: PHP
|
http://www.php-security.org/MOPB/MOPB-34-2007.html
CVE-2007-1718
|
|