PT-2006-2051 · Php+1 · Php+1

Publicado

2006-03-06

·

Atualizado

2018-10-18

·

CVE-2006-1014

CVSS v2.0

3.2

Baixa

VetorAV:L/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP versions 4.x through 5.x
Description The issue allows context-dependent attackers to read and create arbitrary files by providing extra arguments to sendmail when the mb send mail function is used with remote input for the additional parameters argument. This is possible when PHP is used with sendmail.
Recommendations For PHP versions 4.x through 5.x, consider restricting the use of the mb send mail function with remote input until a proper fix is applied, and avoid using the additional parameters argument with untrusted input to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1014

Produtos afetados

Php
Sendmail