The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy."
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:40
Type | Values Removed | Values Added |
---|---|---|
References | () ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-008.0.txt - | |
References | () http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000545 - | |
References | () http://marc.info/?l=bugtraq&m=103011916928204&w=2 - | |
References | () http://marc.info/?l=bugtraq&m=105760591228031&w=2 - | |
References | () http://www.debian.org/security/2002/dsa-168 - | |
References | () http://www.kb.cert.org/vuls/id/410609 - US Government Resource | |
References | () http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:082 - | |
References | () http://www.novell.com/linux/security/advisories/2002_036_modphp4.html - | |
References | () http://www.osvdb.org/2160 - | |
References | () http://www.redhat.com/support/errata/RHSA-2002-213.html - | |
References | () http://www.redhat.com/support/errata/RHSA-2002-214.html - | |
References | () http://www.redhat.com/support/errata/RHSA-2002-243.html - | |
References | () http://www.redhat.com/support/errata/RHSA-2002-244.html - | |
References | () http://www.redhat.com/support/errata/RHSA-2002-248.html - | |
References | () http://www.redhat.com/support/errata/RHSA-2003-159.html - | |
References | () http://www.securityfocus.com/bid/5562 - Patch, Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/9959 - |
Information
Published : 2002-09-24 04:00
Updated : 2024-11-20 23:40
NVD link : CVE-2002-0986
Mitre link : CVE-2002-0986
CVE.ORG link : CVE-2002-0986
JSON object : View
Products Affected
php
- php
CWE