|
php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login |
PatchesPull RequestsHistoryAllCommentsChangesGit/SVN commits
[2010-04-30 16:18 UTC] pajoye@php.net
-Status: Open
+Status: Bogus
[2010-04-30 16:18 UTC] pajoye@php.net
[2010-06-14 11:01 UTC] anon at anon dot com
|
|||||||||||||||||||||||||||
Copyright © 2001-2025 The PHP GroupAll rights reserved. |
Last updated: Sat Oct 25 18:00:02 2025 UTC |
Description: ------------ <?php $to = 'nobody@example.com'; $subject = 'the subject'; $message = 'hello'; $headers = 'From: someoneelse@example.com' . "\r\n" . 'Reply-To: webmaster@example.com' . "\r\n" . 'X-Mailer: PHP/' . phpversion(); mail($to, $subject, $message, $headers); ?> One can mail anyone using someone else's email address without authentication. No password is required. $to = 'anybody@example.com' 'From: someoneelse@example.com' "SERIOUS SECURITY ISSUE" Bug detected By: DEVESH GOYAL Expected result: ---------------- Must ask for password for the email address which is used in 'From: someoneelse@example.com' "SERIOUS SECURITY ISSUE" Bug detected By: DEVESH GOYAL