PT-2006-2051 · Php+1 · Php+1

Published

2006-03-06

·

Updated

2018-10-18

·

CVE-2006-1014

CVSS v2.0

3.2

Low

VectorAV:L/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP versions 4.x through 5.x
Description The issue allows context-dependent attackers to read and create arbitrary files by providing extra arguments to sendmail when the mb send mail function is used with remote input for the additional parameters argument. This is possible when PHP is used with sendmail.
Recommendations For PHP versions 4.x through 5.x, consider restricting the use of the mb send mail function with remote input until a proper fix is applied, and avoid using the additional parameters argument with untrusted input to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1014

Affected Products

Php
Sendmail