NVD

Id
59737  
Name
CVE-2006-1014  
Description
Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.  
Reject
 
CVSS Version
2  
CVSS Score
3.2  
Severity
Low  
CVSS Base Score
3.2  
CVSS Impact Subscore
4.9  
CVSS Exploit Subscore
3.1  
CVSS Vector
(AV:L/AC:L/Au:S/C:P/I:P/A:N)  
Pub Date
2016-12-20  
Published
2006-03-06  
Modified Date
2011-03-07  
Seq
2006-1014  

Actions