xoops forums

Yurdal

Friend of XOOPS
Posted on: 12/28 11:57
Yurdal
Yurdal (Show more)
Friend of XOOPS
Posts: 313
Since: 2005/3/27
#1

PHP Mailer exploit Xoops ?

Have xoops phpmailer included ? if yes will it be updated ?
https://www.exploit-db.com/exploits/40968/

Yurdal

Friend of XOOPS
Posted on: 12/28 17:27
Yurdal
Yurdal (Show more)
Friend of XOOPS
Posts: 313
Since: 2005/3/27
#2

Re: PHP Mailer exploit Xoops ?

ok i have found the phpmail directory in Xoops, its inside:

/class/mail/phpmailer i dont hear anything from the developers here so i did this:

First download the last version 5.2.21 from GIT:

https://github.com/PHPMailer/PHPMailer

After that i overwrote the files from the zip with that ones from this map /class/mail/phpmailer

Everything seems fine so i strongly suggest to do this ASAP

geekwright

Quite a regular
Posted on: 12/28 22:51
geekwright
geekwright (Show more)
Quite a regular
Posts: 218
Since: 2010/10/15
#3

Re: PHP Mailer exploit Xoops ?

Dev's been busy tracking a moving target (PHPMailer had 4 releases in 2 days.)

Just copying in 5.2.21 won't work for every installation, as there were some changes in how the classes were organized. It should work if the transport is PHP mail(), but other configurations may fail without some changes to XoopsMultiMailer.

But, the vulnerability only affects the PHP mail() transport. If the Email delivery method configuration is set to SMTP or sendmail, the vulnerability does not apply.

Good description of the bugs at github.com/PHPMailer/PHPMailer/

The issue depends on a user input of the from address that contains the exploit code. XOOPS core uses a fixed config for the from address, so that mitigates the risk.

Working out the plans for a security patch. Detail will follow when ready and tested.