CVE-2002-0985
Summary
| CVE | CVE-2002-0985 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-09-24 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 'PHP: Bypass safe_mode and inject ASCII control chars with mail()' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| '[OpenPKG-SA-2003.032] OpenPKG Security Advisory (php)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| Mandrakesoft Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | www.mandrakesoft.com | Broken Link |
| ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-008.0.txt | af854a3a-2127-422b-91ae-364da2661108 | ftp.caldera.com | Broken Link |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| Debian -- Security Information -- DSA-168-1 php | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Broken Link, Patch, Vendor Advisory |
| NOVELL: Broken Link - 404 Error Pages | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | Broken Link |
| Home - Conectiva | af854a3a-2127-422b-91ae-364da2661108 | distro.conectiva.com.br | Broken Link |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| www.osvdb.org/2111 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Broken Link |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link, Patch, Vendor Advisory |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.