V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2001-1246
CVE
HighConfirmedExploit available

PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possi…

CVSS
7.5
High
EPSS
0.10
p94
Published
2001-01-01
Updated
2001-01-01
Description

PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.

Tags · CWE
CWE-88
CAPEC-41
CAPEC-88
CAPEC-137
CAPEC-174
CAPEC-460
Affected products
Php 4.0.5–4.1.0
CVSS vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Timeline
2001-01-01
Published
2001-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.097 · p94
Known exploited (KEV)
No
Known exploits — Сканер-ВС
20985
exploitdb · https://www.exploit-db.com/exploits/20985
Enterprise
Affected products
ProductVendorStatus
php*Tracked
Source databases
CVE