CVE
- Id
- 5373
- CVE No.
- CVE-2002-0985
- Status
- Entry
- Description
- Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.
- Phase
- Votes
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
28879 | 5373 | CVE-2002-0985 | BUGTRAQ:20020823 PHP: Bypass safe_mode and inject ASCII control chars with mail() | View |
28880 | 5373 | CVE-2002-0985 | URL:http://marc.info/?l=bugtraq&m=103011916928204&w=2 | View |
28881 | 5373 | CVE-2002-0985 | DEBIAN:DSA-168 | View |
28882 | 5373 | CVE-2002-0985 | URL:http://www.debian.org/security/2002/dsa-168 | View |
28883 | 5373 | CVE-2002-0985 | REDHAT:RHSA-2002:213 | View |
28884 | 5373 | CVE-2002-0985 | URL:http://www.redhat.com/support/errata/RHSA-2002-213.html | View |
28885 | 5373 | CVE-2002-0985 | REDHAT:RHSA-2002:214 | View |
28886 | 5373 | CVE-2002-0985 | URL:http://www.redhat.com/support/errata/RHSA-2002-214.html | View |
28887 | 5373 | CVE-2002-0985 | REDHAT:RHSA-2002:243 | View |
28888 | 5373 | CVE-2002-0985 | URL:http://www.redhat.com/support/errata/RHSA-2002-243.html | View |
28889 | 5373 | CVE-2002-0985 | REDHAT:RHSA-2002:244 | View |
28890 | 5373 | CVE-2002-0985 | URL:http://www.redhat.com/support/errata/RHSA-2002-244.html | View |
28891 | 5373 | CVE-2002-0985 | REDHAT:RHSA-2002:248 | View |
28892 | 5373 | CVE-2002-0985 | URL:http://www.redhat.com/support/errata/RHSA-2002-248.html | View |
28893 | 5373 | CVE-2002-0985 | REDHAT:RHSA-2003:159 | View |
28894 | 5373 | CVE-2002-0985 | URL:http://www.redhat.com/support/errata/RHSA-2003-159.html | View |
28895 | 5373 | CVE-2002-0985 | SUSE:SuSE-SA:2002:036 | View |
28896 | 5373 | CVE-2002-0985 | URL:http://www.novell.com/linux/security/advisories/2002_036_modphp4.html | View |
28897 | 5373 | CVE-2002-0985 | CONECTIVA:CLA-2002:545 | View |
28898 | 5373 | CVE-2002-0985 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000545 | View |
28899 | 5373 | CVE-2002-0985 | CALDERA:CSSA-2003-008.0 | View |
28900 | 5373 | CVE-2002-0985 | URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-008.0.txt | View |
28901 | 5373 | CVE-2002-0985 | XF:php-mail-safemode-bypass(9966) | View |
28902 | 5373 | CVE-2002-0985 | URL:http://xforce.iss.net/xforce/xfdb/9966 | View |
28903 | 5373 | CVE-2002-0985 | BUGTRAQ:20030707 [OpenPKG-SA-2003.032] OpenPKG Security Advisory (php) | View |
28904 | 5373 | CVE-2002-0985 | URL:http://marc.info/?l=bugtraq&m=105760591228031&w=2 | View |
28905 | 5373 | CVE-2002-0985 | MANDRAKE:MDKSA-2003:082 | View |
28906 | 5373 | CVE-2002-0985 | URL:http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:082 | View |
28907 | 5373 | CVE-2002-0985 | OSVDB:2111 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
63944 | JVNDB-2002-000271 | PHP の mail() 関数 における safe_mode オプションによる制限を回避される脆弱性 | ------------ | CVE-2002-0985 | 5373 | 7.5 | http://jvndb.jvn.jp/ja/contents/2002/JVNDB-2002-000271.html | View |