<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: PHPMailer 0day remote command execution</title>
	<atom:link href="http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/feed/" rel="self" type="application/rss+xml" />
	<link>http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/</link>
	<description>Me, myself and I</description>
	<pubDate>Tue, 07 Oct 2008 22:59:03 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: Mantis Bug Tracker Blog &#187; Blog Archive &#187; Evaluating a PHPMailer Vulnerability</title>
		<link>http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/#comment-860</link>
		<dc:creator>Mantis Bug Tracker Blog &#187; Blog Archive &#187; Evaluating a PHPMailer Vulnerability</dc:creator>
		<pubDate>Mon, 16 Jul 2007 06:53:22 +0000</pubDate>
		<guid isPermaLink="false">http://test.larholm.com/?p=13#comment-860</guid>
		<description>[...] sender address can be used to gain access to system resources. This exploit is described in &#8220;PHPMailer 0day remote command execution&#8221; and [...]</description>
		<content:encoded><![CDATA[<p>[...] sender address can be used to gain access to system resources. This exploit is described in &#8220;PHPMailer 0day remote command execution&#8221; and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: NafieCarL.Com &#124; About Blogging, eBiz &#38; Advertisement &#187; News - Three holes closed in WordPress</title>
		<link>http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/#comment-427</link>
		<dc:creator>NafieCarL.Com &#124; About Blogging, eBiz &#38; Advertisement &#187; News - Three holes closed in WordPress</dc:creator>
		<pubDate>Sun, 01 Jul 2007 11:11:26 +0000</pubDate>
		<guid isPermaLink="false">http://test.larholm.com/?p=13#comment-427</guid>
		<description>[...] PHPMailer 0day remote command execution, Thor Larholm&#8217;s security advisory [...]</description>
		<content:encoded><![CDATA[<p>[...] PHPMailer 0day remote command execution, Thor Larholm&#8217;s security advisory [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: developercast.com &#187; Symfony Blog: symfony 1.0.5 released (security fix)</title>
		<link>http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/#comment-381</link>
		<dc:creator>developercast.com &#187; Symfony Blog: symfony 1.0.5 released (security fix)</dc:creator>
		<pubDate>Thu, 28 Jun 2007 15:47:42 +0000</pubDate>
		<guid isPermaLink="false">http://test.larholm.com/?p=13#comment-381</guid>
		<description>[...] The Symfony project has released the latest version of their framework - Symfony 1.0.5 - largely a security fix release to help head off some issues that came up with the phpmailer utility.   I&#8217;ve just released symfony 1.0.5. If you use the symfony built-in phpmailer (and you do if you use the -&#62;sendMail() method in your actions), you must upgrade to this release or apply the following patch: http://trac.symfony-project.com/trac/changeset/4380?format=diff&#38;new=4380. PHPMailer has a remote command execution vulnerability if you have configured it to use sendmail. You can find more information about this issue here: http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/ [...]</description>
		<content:encoded><![CDATA[<p>[...] The Symfony project has released the latest version of their framework - Symfony 1.0.5 - largely a security fix release to help head off some issues that came up with the phpmailer utility.   I&#8217;ve just released symfony 1.0.5. If you use the symfony built-in phpmailer (and you do if you use the -&gt;sendMail() method in your actions), you must upgrade to this release or apply the following patch: <a href="http://trac.symfony-project.com/trac/changeset/4380?format=diff&amp;new=4380" rel="nofollow">http://trac.symfony-project.com/trac/changeset/4380?format=diff&amp;new=4380</a>. PHPMailer has a remote command execution vulnerability if you have configured it to use sendmail. You can find more information about this issue here: <a href="http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/" rel="nofollow">http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Larholm.com - Me, myself and I &#187; PHPMailer security updates</title>
		<link>http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/#comment-361</link>
		<dc:creator>Larholm.com - Me, myself and I &#187; PHPMailer security updates</dc:creator>
		<pubDate>Wed, 27 Jun 2007 04:15:42 +0000</pubDate>
		<guid isPermaLink="false">http://test.larholm.com/?p=13#comment-361</guid>
		<description>[...] security updates   By Thor Larholm On June 11 I published an input validation vulnerability in PHPMailer, CVE-2007-3215. Since then, a number of applications [...]</description>
		<content:encoded><![CDATA[<p>[...] security updates   By Thor Larholm On June 11 I published an input validation vulnerability in PHPMailer, CVE-2007-3215. Since then, a number of applications [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rpsblog.com &#187; symfony 1.0.5 released (security fix)</title>
		<link>http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/#comment-351</link>
		<dc:creator>rpsblog.com &#187; symfony 1.0.5 released (security fix)</dc:creator>
		<pubDate>Tue, 26 Jun 2007 14:38:22 +0000</pubDate>
		<guid isPermaLink="false">http://test.larholm.com/?p=13#comment-351</guid>
		<description>[...] PHPMailer has a remote command execution vulnerability if you have configured it to use sendmail. You can find more information about this issue here: http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/ [...]</description>
		<content:encoded><![CDATA[<p>[...] PHPMailer has a remote command execution vulnerability if you have configured it to use sendmail. You can find more information about this issue here: <a href="http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/" rel="nofollow">http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: symfony 1.0.5 released at ???Blog</title>
		<link>http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/#comment-343</link>
		<dc:creator>symfony 1.0.5 released at ???Blog</dc:creator>
		<pubDate>Tue, 26 Jun 2007 03:27:19 +0000</pubDate>
		<guid isPermaLink="false">http://test.larholm.com/?p=13#comment-343</guid>
		<description>[...] PHPMailer  ?????sendmail????????????????????http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/ [...]</description>
		<content:encoded><![CDATA[<p>[...] PHPMailer  ?????sendmail????????????????????http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/ [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PHPMailer????</title>
		<link>http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/#comment-287</link>
		<dc:creator>PHPMailer????</dc:creator>
		<pubDate>Sun, 17 Jun 2007 02:26:30 +0000</pubDate>
		<guid isPermaLink="false">http://test.larholm.com/?p=13#comment-287</guid>
		<description>[...] PHPMailer????????????????????????????????popen????????????????????????????????????????????fork??????????????WordPress??wp-includes/class-phpmailer.php????????????????????? [...]</description>
		<content:encoded><![CDATA[<p>[...] PHPMailer????????????????????????????????popen????????????????????????????????????????????fork??????????????WordPress??wp-includes/class-phpmailer.php????????????????????? [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gordon Franke</title>
		<link>http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/#comment-72</link>
		<dc:creator>Gordon Franke</dc:creator>
		<pubDate>Tue, 12 Jun 2007 13:08:28 +0000</pubDate>
		<guid isPermaLink="false">http://test.larholm.com/?p=13#comment-72</guid>
		<description>there is a Plugin for Symfony to use the Swift Mailer:
http://trac.symfony-project.com/trac/wiki/sfSwiftPlugin</description>
		<content:encoded><![CDATA[<p>there is a Plugin for Symfony to use the Swift Mailer:<br />
<a href="http://trac.symfony-project.com/trac/wiki/sfSwiftPlugin" rel="nofollow">http://trac.symfony-project.com/trac/wiki/sfSwiftPlugin</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kamilion</title>
		<link>http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/#comment-71</link>
		<dc:creator>Kamilion</dc:creator>
		<pubDate>Mon, 11 Jun 2007 23:54:03 +0000</pubDate>
		<guid isPermaLink="false">http://test.larholm.com/?p=13#comment-71</guid>
		<description>Swiftmailer doesn't have this problem, and has a PHPMailer shim.

http://www.swiftmailer.org/</description>
		<content:encoded><![CDATA[<p>Swiftmailer doesn&#8217;t have this problem, and has a PHPMailer shim.</p>
<p><a href="http://www.swiftmailer.org/" rel="nofollow">http://www.swiftmailer.org/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thor Larholm</title>
		<link>http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/#comment-70</link>
		<dc:creator>Thor Larholm</dc:creator>
		<pubDate>Mon, 11 Jun 2007 11:19:32 +0000</pubDate>
		<guid isPermaLink="false">http://test.larholm.com/?p=13#comment-70</guid>
		<description>A quick note:

The &lt;a href="http://www.symfony-project.com/" rel="nofollow"&gt;Symfony&lt;/a&gt; web PHP framework uses PHPMailer as its base emailer utility.</description>
		<content:encoded><![CDATA[<p>A quick note:</p>
<p>The <a href="http://www.symfony-project.com/" rel="nofollow">Symfony</a> web PHP framework uses PHPMailer as its base emailer utility.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
