7.5
CVSSv2

CVE-2001-1246

Published: 30/06/2001 Updated: 14/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP 4.0.5 up to and including 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote malicious users to execute arbitrary commands via shell metacharacters.

Vulnerable Product Search on Vulmon Subscribe to Product

php php

Exploits

source: wwwsecurityfocuscom/bid/2954/info PHP is the Personal HomePage development toolkit, distributed by the PHPnet, and maintained by the PHP Development Team in public domain A problem with the toolkit could allow elevated privileges, and potentially unauthorized access to restricted resources A local user may upload a malicious p ...