CVE Database
/

CVE-2006-1015

Back to search

CVE-2006-1015

Published: Mar 7, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

VendorProductVersions

n/a

n/a

affected
n/a

References

16878
vdb-entry
x_refsource_BID
19979
third-party-advisory
x_refsource_SECUNIA
517
third-party-advisory
x_refsource_SREASON
SUSE-SA:2006:024
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now