This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include
, or for example
via PHP's auto-loading mechanism.
These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more
1 | <?php |
||
2 | |||
3 | /** |
||
4 | * This file is part of Peachy MediaWiki Bot API |
||
5 | * |
||
6 | * Peachy is free software: you can redistribute it and/or modify |
||
7 | * it under the terms of the GNU General Public License as published by |
||
8 | * the Free Software Foundation, either version 3 of the License, or |
||
9 | * (at your option) any later version. |
||
10 | * |
||
11 | * This program is distributed in the hope that it will be useful, |
||
12 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
||
13 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
||
14 | * GNU General Public License for more details. |
||
15 | * |
||
16 | * You should have received a copy of the GNU General Public License |
||
17 | * along with this program. If not, see <http://www.gnu.org/licenses/>. |
||
18 | */ |
||
19 | |||
20 | class Email { |
||
21 | /** |
||
22 | * Who to send to |
||
23 | * @var array |
||
24 | */ |
||
25 | private $mTo = array(); |
||
26 | |||
27 | /** |
||
28 | * Who the message is from |
||
29 | * @var array |
||
30 | */ |
||
31 | private $mFrom = array(); |
||
32 | |||
33 | /** |
||
34 | * Subject |
||
35 | * @var string |
||
36 | */ |
||
37 | private $mSubject; |
||
38 | |||
39 | /** |
||
40 | * Message to send |
||
41 | * @var string |
||
42 | */ |
||
43 | private $mMessage; |
||
44 | |||
45 | /** |
||
46 | * CC field |
||
47 | * @var array |
||
48 | */ |
||
49 | private $mCC = array(); |
||
50 | |||
51 | /** |
||
52 | * BCC field |
||
53 | * @var array |
||
54 | */ |
||
55 | private $mBCC = array(); |
||
56 | |||
57 | /** |
||
58 | * Reply-to field |
||
59 | * @var array |
||
60 | */ |
||
61 | private $mRT = array(); |
||
62 | |||
63 | /** |
||
64 | * Construct function, adds the From: field, subject, and message |
||
65 | * @param string $fromEmail Email address of sender |
||
66 | * @param string $fromName Name of sender. |
||
67 | * @param string $subject Subject of email |
||
68 | * @param string $message Message to send |
||
69 | * @throws DependencyError |
||
70 | */ |
||
71 | function __construct( $fromEmail, $fromName, $subject, $message ) { |
||
72 | |||
73 | if( !function_exists( 'mail' ) ) { |
||
74 | throw new DependencyError( "Mail", "http://us4.php.net/manual/en/book.mail.php" ); |
||
0 ignored issues
–
show
|
|||
75 | } |
||
76 | |||
77 | if( !is_null( $fromName ) ) { |
||
78 | $this->mFrom[$fromName] = $fromEmail; |
||
79 | } else { |
||
80 | $this->mFrom[] = $fromEmail; |
||
81 | } |
||
82 | $this->mSubject = $subject; |
||
83 | $this->mMessage = $message; |
||
84 | } |
||
85 | |||
86 | /** |
||
87 | * Adds another email to the To: field. |
||
88 | * @param string $toEmail Email address of recipient |
||
89 | * @param string $toName Name of recipient. Default null |
||
90 | */ |
||
91 | public function addTarget( $toEmail, $toName = null ) { |
||
92 | if( !is_null( $toName ) ) { |
||
93 | $this->mTo[$toName] = $toEmail; |
||
94 | } else { |
||
95 | $this->mTo[] = $toEmail; |
||
96 | } |
||
97 | } |
||
98 | |||
99 | /** |
||
100 | * Adds another email to the CC: field. |
||
101 | * @param string $ccEmail Email address of cc |
||
102 | * @param string $ccName Name of cc. Default null |
||
103 | */ |
||
104 | public function addCC( $ccEmail, $ccName = null ) { |
||
105 | if( !is_null( $ccName ) ) { |
||
106 | $this->mCC[$ccName] = $ccEmail; |
||
107 | } else { |
||
108 | $this->mCC[] = $ccEmail; |
||
109 | } |
||
110 | } |
||
111 | |||
112 | /** |
||
113 | * Adds another email to the BCC: field. |
||
114 | * @param string $bccEmail Email address of bcc |
||
115 | * @param string $bccName Name of bcc. Default null |
||
116 | */ |
||
117 | public function addBCC( $bccEmail, $bccName = null ) { |
||
118 | if( !is_null( $bccName ) ) { |
||
119 | $this->mBCC[$bccName] = $bccEmail; |
||
120 | } else { |
||
121 | $this->mBCC[] = $bccEmail; |
||
122 | } |
||
123 | } |
||
124 | |||
125 | /** |
||
126 | * Adds another email to the Reply-to: field. |
||
127 | * @param string $rtEmail Email address to reply to |
||
128 | * @param string $rtName Name to reply to. Default null |
||
129 | */ |
||
130 | public function addReplyTo( $rtEmail, $rtName = null ) { |
||
131 | if( !is_null( $rtName ) ) { |
||
132 | $this->mRT[$rtName] = $rtEmail; |
||
133 | } else { |
||
134 | $this->mRT[] = $rtEmail; |
||
135 | } |
||
136 | } |
||
137 | |||
138 | /** |
||
139 | * Sends the email. |
||
140 | */ |
||
141 | public function send() { |
||
142 | $msg = array(); |
||
143 | |||
144 | $msg_to = array(); |
||
145 | foreach( $this->mTo as $name => $target ){ |
||
146 | if( !is_string( $name ) ) { |
||
147 | $msg_to[] = $target; |
||
148 | } else { |
||
149 | $msg_to[] = "$name <$target>"; |
||
150 | } |
||
151 | } |
||
152 | $msg['to'] = implode( ', ', $msg_to ); |
||
153 | |||
154 | $msg_from = array(); |
||
155 | foreach( $this->mFrom as $name => $target ){ |
||
156 | if( !is_string( $name ) ) { |
||
157 | $msg_from[] = $target; |
||
158 | } else { |
||
159 | $msg_from[] = "$name <$target>"; |
||
160 | } |
||
161 | } |
||
162 | $msg['from'] = null; |
||
163 | if( count( $msg_from ) > 0 ) $msg['from'] = "From: " . implode( ', ', $msg_from ); |
||
164 | |||
165 | $msg_cc = array(); |
||
166 | foreach( $this->mCC as $name => $target ){ |
||
167 | if( !is_string( $name ) ) { |
||
168 | $msg_cc[] = $target; |
||
169 | } else { |
||
170 | $msg_cc[] = "$name <$target>"; |
||
171 | } |
||
172 | } |
||
173 | $msg['cc'] = null; |
||
174 | if( count( $msg_cc ) > 0 ) $msg['cc'] = "CC: " . implode( ', ', $msg_cc ); |
||
175 | |||
176 | $msg_bcc = array(); |
||
177 | foreach( $this->mBCC as $name => $target ){ |
||
178 | if( !is_string( $name ) ) { |
||
179 | $msg_bcc[] = $target; |
||
180 | } else { |
||
181 | $msg_bcc[] = "$name"; |
||
182 | } |
||
183 | } |
||
184 | $msg['bcc'] = null; |
||
185 | if( count( $msg_bcc ) > 0 ) $msg['bcc'] = "BCC: " . implode( ', ', $msg_bcc ); |
||
186 | |||
187 | $msg_rt = array(); |
||
188 | foreach( $this->mRT as $name => $target ){ |
||
189 | if( !is_string( $name ) ) { |
||
190 | $msg_rt[] = $target; |
||
191 | } else { |
||
192 | $msg_rt[] = "$name <$target>"; |
||
193 | } |
||
194 | } |
||
195 | $msg['rt'] = null; |
||
196 | if( count( $msg_rt ) > 0 ) $msg['rt'] = "Reply-to: " . implode( ', ', $msg_rt ); |
||
197 | |||
198 | $msg['subject'] = $this->mSubject; |
||
199 | $msg['message'] = $this->mMessage; |
||
200 | $msg['version'] = 'X-Mailer: PHP/' . phpversion(); |
||
201 | |||
202 | $msg['headers'] = $msg['from'] . "\r\n"; |
||
203 | if( !is_null( $msg['rt'] ) ) $msg['headers'] .= $msg['rt'] . "\r\n"; |
||
204 | if( !is_null( $msg['cc'] ) ) $msg['headers'] .= $msg['cc'] . "\r\n"; |
||
205 | if( !is_null( $msg['bcc'] ) ) $msg['headers'] .= $msg['bcc'] . "\r\n"; |
||
206 | $msg['headers'] .= $msg['version']; |
||
207 | |||
208 | $result = mail( $msg['to'], $msg['subject'], $msg['message'], $msg['headers'] ); |
||
209 | |||
210 | return $result; |
||
211 | } |
||
212 | } |
||
213 |
It seems like the type of the argument is not accepted by the function/method which you are calling.
In some cases, in particular if PHP’s automatic type-juggling kicks in this might be fine. In other cases, however this might be a bug.
We suggest to add an explicit type cast like in the following example: