Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2002-0985
Description:Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.
Test IDs: 1.3.6.1.4.1.25623.1.0.54132  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2002-0985
Bugtraq: 20020823 PHP: Bypass safe_mode and inject ASCII control chars with mail() (Google Search)
http://marc.info/?l=bugtraq&m=103011916928204&w=2
Bugtraq: 20030707 [OpenPKG-SA-2003.032] OpenPKG Security Advisory (php) (Google Search)
http://marc.info/?l=bugtraq&m=105760591228031&w=2
Caldera Security Advisory: CSSA-2003-008.0
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-008.0.txt
Conectiva Linux advisory: CLA-2002:545
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000545
Debian Security Information: DSA-168 (Google Search)
http://www.debian.org/security/2002/dsa-168
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:082
http://www.osvdb.org/2111
RedHat Security Advisories: RHSA-2002:213
http://www.redhat.com/support/errata/RHSA-2002-213.html
RedHat Security Advisories: RHSA-2002:214
http://www.redhat.com/support/errata/RHSA-2002-214.html
RedHat Security Advisories: RHSA-2002:243
http://www.redhat.com/support/errata/RHSA-2002-243.html
RedHat Security Advisories: RHSA-2002:244
http://www.redhat.com/support/errata/RHSA-2002-244.html
RedHat Security Advisories: RHSA-2002:248
http://www.redhat.com/support/errata/RHSA-2002-248.html
RedHat Security Advisories: RHSA-2003:159
http://www.redhat.com/support/errata/RHSA-2003-159.html
SuSE Security Announcement: SuSE-SA:2002:036 (Google Search)
http://www.novell.com/linux/security/advisories/2002_036_modphp4.html
XForce ISS Database: php-mail-safemode-bypass(9966)
https://exchange.xforce.ibmcloud.com/vulnerabilities/9966




© 1998-2025 E-Soft Inc. All rights reserved.