Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Php | — | Upgrade to PHP version 5.2.0 | Oct 1, 2012 | Mar 6, 2006 |
| Suse | — | Upgrade php4-exifUpgrade php4-mbstringUpgrade php4-develUpgrade mod_php4-servletUpgrade php4-recodeUpgrade mod_php4-coreUpgrade php4-fastcgiUpgrade php4-sysvshmUpgrade apache-mod_php4Upgrade php4-imapUpgrade php4-pearUpgrade apache2-mod_php4Upgrade php4-sessionUpgrade php4-mysql | Feb 17, 2015 | Mar 6, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub