ID:               21931
 Updated by:       [EMAIL PROTECTED]
 Reported By:      php dot net at spamfilter dot friendlydude dot com
-Status:           Open
+Status:           Closed
 Bug Type:         Feature/Change Request
 Operating System: Linux 2.4.19
 PHP Version:      4.3.0
 New Comment:

This bug has been fixed in CVS.

In case this was a PHP problem, snapshots of the sources are packaged
every three hours; this change will be in the next snapshot. You can
grab the snapshot at http://snaps.php.net/.
 
In case this was a documentation problem, the fix will show up soon at
http://www.php.net/manual/.

In case this was a PHP.net website problem, the change will show
up on the PHP.net site and on the mirror sites in short time.
 
Thank you for the report, and for helping us make PHP better.

It is NOT enabled now in safe mode, but atleast you can force it with
the ini setting "mail_force_extra_parameters", see also:
http://news.php.net/article.php?group=php.cvs&article=19210

Derick



Previous Comments:
------------------------------------------------------------------------

[2003-01-29 13:40:26] [EMAIL PROTECTED]

This is a feature/change request. 

------------------------------------------------------------------------

[2003-01-29 03:10:55] php dot net at spamfilter dot friendlydude dot
com

The fifth parameter of the mail() function is disabled in safe_mode,
but the changelog says the security issue is already fixed:

Changed mail() to use escape_shell_cmd() to allow multiple extra
parameters to the invocation of the mailer as used in the fifth
parameter. (Derick)

Can it be enabled in the next version of php?

------------------------------------------------------------------------


-- 
Edit this bug report at http://bugs.php.net/?id=21931&edit=1

Reply via email to