Re: [PHP-DEV] mail.force_extra_parameters

2007-09-13 Thread Jacques Marneweck
On 13 Sep 2007, at 1:04 AM, David Coallier wrote: On 9/12/07, Stanislav Malyshev <[EMAIL PROTECTED]> wrote: Would anyone object to disallowing setting mail.force_extra_parameters from .htaccess? The problem is that mail.force_extra_parameters can pass arbitrary arguments to mail tool, and s

Re: [PHP-DEV] mail.force_extra_parameters

2007-09-12 Thread David Coallier
On 9/12/07, Stanislav Malyshev <[EMAIL PROTECTED]> wrote: > Would anyone object to disallowing setting mail.force_extra_parameters > from .htaccess? The problem is that mail.force_extra_parameters can pass > arbitrary arguments to mail tool, and some mail tools (especially one, > guess which ;) hav

[PHP-DEV] mail.force_extra_parameters

2007-09-12 Thread Stanislav Malyshev
Would anyone object to disallowing setting mail.force_extra_parameters from .htaccess? The problem is that mail.force_extra_parameters can pass arbitrary arguments to mail tool, and some mail tools (especially one, guess which ;) have a lot of parameters, that allow, in particular, reading and