VDB
CVE-2002-0985
CVE-2002-0985
PUBLISHED
CVSS 7.5 HIGH
Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.
EPSS 2.95% · 86.3th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
2.95%
86.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| php | php | 4.0 |
| n/a | n/a | n/a |
| openpkg | openpkg | 1.1, 1.2 |
Timeline
- Sep 24, 2002 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
References
- RHSA-2002:248 vendor-advisory
- 20030707 [OpenPKG-SA-2003.032] OpenPKG Security Advisory (php) mailing-list
- php-mail-safemode-bypass(9966) vdb
- 20020823 PHP: Bypass safe_mode and inject ASCII control chars with mail() mailing-list
- RHSA-2002:243 vendor-advisory
- CLA-2002:545 vendor-advisory
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-008.0.txt technical
- http://www.debian.org/security/2002/dsa-168 technical
- http://www.novell.com/linux/security/advisories/2002_036_modphp4.html technical
- http://www.osvdb.org/2111 technical
- http://www.redhat.com/support/errata/RHSA-2002-214.html technical
- http://www.redhat.com/support/errata/RHSA-2002-244.html technical
- http://www.redhat.com/support/errata/RHSA-2003-159.html technical
- https://nvd.nist.gov/vuln/detail/CVE-2002-0985 advisory
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:082 url
- http://www.redhat.com/support/errata/RHSA-2002-213.html url