|
|
Info |
Last Modified |
| about 1 year ago |
|
|
|
|
|
Description |
PHP's ext/filter extension contains a flaw that may allow a malicious user to inject specially crafted mail headers. The issue is triggered due to the FILTER_VALIDATE_EMAIL function using an incorrect regular expression which can be trivially bypassed. By using a newline character, an attacker could potentially use this to send unsolicited e-mail from the host.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
OSVDB:
Web Related
|
|
Solution |
Upgrade to version 5.2.3 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
PHP
 |
5.2.0 |
5.2.1 |
|
|
|
|
|
|
Credit |
- Stefan Esser - sesser
hardenend-php.net - Hardened-PHP Project
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|