CVE Database
/

CVE-2002-0986

Back to search

CVE-2002-0986

Published: Sep 1, 2004

Modified: Aug 8, 2024

PUBLISHED

Description

The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy."

VendorProductVersions

n/a

n/a

affected
n/a

References

DSA-168
vendor-advisory
x_refsource_DEBIAN
VU#410609
third-party-advisory
x_refsource_CERT-VN
RHSA-2002:243
vendor-advisory
x_refsource_REDHAT
2160
vdb-entry
x_refsource_OSVDB
RHSA-2003:159
vendor-advisory
x_refsource_REDHAT
MDKSA-2003:082
vendor-advisory
x_refsource_MANDRAKE
5562
vdb-entry
x_refsource_BID
php-mail-ascii-injection(9959)
vdb-entry
x_refsource_XF
SuSE-SA:2002:036
vendor-advisory
x_refsource_SUSE
CLA-2002:545
vendor-advisory
x_refsource_CONECTIVA
RHSA-2002:213
vendor-advisory
x_refsource_REDHAT
RHSA-2002:248
vendor-advisory
x_refsource_REDHAT
RHSA-2002:244
vendor-advisory
x_refsource_REDHAT
RHSA-2002:214
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now