Lucene search

K
cve[email protected]CVE-2002-0985
HistorySep 01, 2004 - 4:00 a.m.

CVE-2002-0985

2004-09-0104:00:00
CWE-88
web.nvd.nist.gov
41
cve-2002-0985
php
argument injection
vulnerability
mail function
bypass
safe mode
mta
sendmail

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.8 Medium

AI Score

Confidence

Low

0.015 Low

EPSS

Percentile

87.1%

Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.

Affected configurations

NVD
Node
phpphpRange4.04.2.2
Node
openpkgopenpkgMatch1.1
OR
openpkgopenpkgMatch1.2
CPENameOperatorVersion
php:phpphple4.2.2

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.8 Medium

AI Score

Confidence

Low

0.015 Low

EPSS

Percentile

87.1%