PT-2006-2052 · Php+1 · Php+1

Ced Clerget Free Fr

·

Publicado

2006-03-06

·

Atualizado

2018-10-30

·

CVE-2006-1015

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP versions 3.x through 5.x
Description The issue allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments when used with sendmail and when accepting remote input for the additional parameters argument to the mail function.
Recommendations For PHP versions 3.x through 5.x, consider restricting access to the mail function or disabling the use of sendmail until a proper fix is applied. As a temporary workaround, avoid using the additional parameters argument in the mail function to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1015

Produtos afetados

Php
Sendmail