Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Php | — | Upgrade to PHP version 5.1.3 | Oct 1, 2012 | Mar 6, 2006 |
| Suse | — | Upgrade php4-fastcgiUpgrade php4-imapUpgrade apache-mod_php4Upgrade php4-sessionUpgrade apache2-mod_php4Upgrade php4-develUpgrade php4-mbstringUpgrade php4-recodeUpgrade php4-mysqlUpgrade php4-exifUpgrade mod_php4-coreUpgrade php4-pearUpgrade php4-sysvshmUpgrade mod_php4-servlet | Feb 17, 2015 | Mar 6, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub