VDB
CVE-2002-0986
CVE-2002-0986
PUBLISHED
CVSS 5 MEDIUM
The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy."
EPSS 4.70% · 91.5th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
4.70%
91.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| php | php | 4.0.2, 4.2.1, 3.0.18 |
| n/a | n/a | n/a |
Timeline
- Sep 24, 2002 CVE Published
- Feb 4, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- Jul 19, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
- Dec 24, 2023 EPSS Score
- Apr 8, 2024 EPSS Score
References
- 20030707 [OpenPKG-SA-2003.032] OpenPKG Security Advisory (php) mailing-list
- RHSA-2002:243 vendor-advisory
- CLA-2002:545 vendor-advisory
- DSA-168 vendor-advisory
- 2160 vdb
- CSSA-2003-008.0 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2002-0986 advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9959 url
- http://www.kb.cert.org/vuls/id/410609 url
- http://www.redhat.com/support/errata/RHSA-2002-248.html url
- http://www.redhat.com/support/errata/RHSA-2003-159.html url
- http://www.redhat.com/support/errata/RHSA-2002-244.html technical
- http://marc.info/?l=bugtraq&m=103011916928204&w=2 technical
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:082 technical
- http://www.novell.com/linux/security/advisories/2002_036_modphp4.html technical
- http://www.redhat.com/support/errata/RHSA-2002-213.html technical
- http://www.redhat.com/support/errata/RHSA-2002-214.html technical
- http://www.securityfocus.com/bid/5562 patch