Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2002-0986
Description:The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy."
Test IDs: 1.3.6.1.4.1.25623.1.0.51836  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2002-0986
BugTraq ID: 5562
http://www.securityfocus.com/bid/5562
Bugtraq: 20020823 PHP: Bypass safe_mode and inject ASCII control chars with mail() (Google Search)
http://marc.info/?l=bugtraq&m=103011916928204&w=2
Bugtraq: 20030707 [OpenPKG-SA-2003.032] OpenPKG Security Advisory (php) (Google Search)
http://marc.info/?l=bugtraq&m=105760591228031&w=2
Caldera Security Advisory: CSSA-2003-008.0
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-008.0.txt
CERT/CC vulnerability note: VU#410609
http://www.kb.cert.org/vuls/id/410609
Conectiva Linux advisory: CLA-2002:545
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000545
Debian Security Information: DSA-168 (Google Search)
http://www.debian.org/security/2002/dsa-168
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:082
http://www.osvdb.org/2160
RedHat Security Advisories: RHSA-2002:213
http://www.redhat.com/support/errata/RHSA-2002-213.html
RedHat Security Advisories: RHSA-2002:214
http://www.redhat.com/support/errata/RHSA-2002-214.html
RedHat Security Advisories: RHSA-2002:243
http://www.redhat.com/support/errata/RHSA-2002-243.html
RedHat Security Advisories: RHSA-2002:244
http://www.redhat.com/support/errata/RHSA-2002-244.html
RedHat Security Advisories: RHSA-2002:248
http://www.redhat.com/support/errata/RHSA-2002-248.html
RedHat Security Advisories: RHSA-2003:159
http://www.redhat.com/support/errata/RHSA-2003-159.html
SuSE Security Announcement: SuSE-SA:2002:036 (Google Search)
http://www.novell.com/linux/security/advisories/2002_036_modphp4.html
XForce ISS Database: php-mail-ascii-injection(9959)
https://exchange.xforce.ibmcloud.com/vulnerabilities/9959




© 1998-2025 E-Soft Inc. All rights reserved.