PT-2002-1992 · Php · Php

Published

2002-09-24

·

Updated

2017-10-10

·

CVE-2002-0986

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: PHP versions 4.x through 4.2.2
Description: The issue concerns the mail function in PHP, which fails to filter ASCII control characters from its arguments. This could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a spam proxy.
Recommendations: For PHP versions 4.x through 4.2.2, update to a version that fixes this issue to prevent potential exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0986
DSA-168

Affected Products

Php