CVE Database
/

CVE-2006-1014

Back to search

CVE-2006-1014

Published: Mar 7, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2006-0772
vdb-entry
x_refsource_VUPEN
23534
vdb-entry
x_refsource_OSVDB
16878
vdb-entry
x_refsource_BID
20060228 (PHP) mb_send_mail security bypass
mailing-list
x_refsource_BUGTRAQ
19979
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2006:024
vendor-advisory
x_refsource_SUSE
18694
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now