PT-2006-2052 · Php+1 · Php+1

Ced Clerget Free Fr

·

Published

2006-03-06

·

Updated

2018-10-30

·

CVE-2006-1015

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP versions 3.x through 5.x
Description The issue allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments when used with sendmail and when accepting remote input for the additional parameters argument to the mail function.
Recommendations For PHP versions 3.x through 5.x, consider restricting access to the mail function or disabling the use of sendmail until a proper fix is applied. As a temporary workaround, avoid using the additional parameters argument in the mail function to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1015

Affected Products

Php
Sendmail