{"api_version":"1","generated_at":"2026-07-23T06:33:59+00:00","cve":"CVE-2001-1246","urls":{"html":"https://cve.report/CVE-2001-1246","api":"https://cve.report/api/cve/CVE-2001-1246.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2001-1246","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2001-1246"},"summary":{"title":"CVE-2001-1246","description":"PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.","state":"PUBLISHED","assigner":"mitre","published_at":"2001-06-30 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-88","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.redhat.com/support/errata/RHSA-2003-159.html","name":"http://www.redhat.com/support/errata/RHSA-2003-159.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/6787.php","name":"http://www.iss.net/security_center/static/6787.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch","Vendor Advisory"],"title":"ISS X-Force Database: php-safemode-elevate-privileges (6787): PHP SafeMode allows user to gain elevated privileges","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://online.securityfocus.com/archive/1/194425","name":"http://online.securityfocus.com/archive/1/194425","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"","mime":"","httpstatus":"-1","archivestatus":"503"},{"url":"http://www.php.net/do_download.php?download_file=php-4.1.2.tar.gz","name":"http://www.php.net/do_download.php?download_file=php-4.1.2.tar.gz","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"PHP: Manual Quick Reference","mime":"text/html","httpstatus":"200","archivestatus":"503"},{"url":"http://www.securityfocus.com/bid/2954","name":"http://www.securityfocus.com/bid/2954","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"504 Gateway Time-out","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.redhat.com/support/errata/RHSA-2002-102.html","name":"http://www.redhat.com/support/errata/RHSA-2002-102.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"504"},{"url":"http://www.redhat.com/support/errata/RHSA-2002-129.html","name":"http://www.redhat.com/support/errata/RHSA-2002-129.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"503"},{"url":"https://www.cve.org/CVERecord?id=CVE-2001-1246","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2001-1246","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2001","cve_id":"1246","vulnerable":"1","versionEndIncluding":"4.1.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"php","cpe5":"php","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T04:51:08.236Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"RHSA-2003:159","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2003-159.html"},{"name":"RHSA-2002:129","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2002-129.html"},{"name":"php-safemode-elevate-privileges(6787)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/6787.php"},{"name":"2954","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/2954"},{"name":"20010630 php breaks safe mode","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://online.securityfocus.com/archive/1/194425"},{"name":"RHSA-2002:102","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2002-102.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.php.net/do_download.php?download_file=php-4.1.2.tar.gz"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2001-06-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2010-01-22T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"RHSA-2003:159","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2003-159.html"},{"name":"RHSA-2002:129","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2002-129.html"},{"name":"php-safemode-elevate-privileges(6787)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/6787.php"},{"name":"2954","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/2954"},{"name":"20010630 php breaks safe mode","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://online.securityfocus.com/archive/1/194425"},{"name":"RHSA-2002:102","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2002-102.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.php.net/do_download.php?download_file=php-4.1.2.tar.gz"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2001-1246","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"RHSA-2003:159","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2003-159.html"},{"name":"RHSA-2002:129","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2002-129.html"},{"name":"php-safemode-elevate-privileges(6787)","refsource":"XF","url":"http://www.iss.net/security_center/static/6787.php"},{"name":"2954","refsource":"BID","url":"http://www.securityfocus.com/bid/2954"},{"name":"20010630 php breaks safe mode","refsource":"BUGTRAQ","url":"http://online.securityfocus.com/archive/1/194425"},{"name":"RHSA-2002:102","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2002-102.html"},{"name":"http://www.php.net/do_download.php?download_file=php-4.1.2.tar.gz","refsource":"CONFIRM","url":"http://www.php.net/do_download.php?download_file=php-4.1.2.tar.gz"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2001-1246","datePublished":"2002-06-25T04:00:00.000Z","dateReserved":"2002-05-01T00:00:00.000Z","dateUpdated":"2024-08-08T04:51:08.236Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2001-06-30 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-88","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0.5","versionEndIncluding":"4.1.0","matchCriteriaId":"AF5EFBC9-2F17-44CD-8298-3D0BA0B48F4C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2001","CveId":"1246","Ordinal":"1","Title":"CVE-2001-1246","CVE":"CVE-2001-1246","Year":"2001"},"notes":[{"CveYear":"2001","CveId":"1246","Ordinal":"1","NoteData":"PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.","Type":"Description","Title":"CVE-2001-1246"},{"CveYear":"2001","CveId":"1246","Ordinal":"2","NoteData":"2002-06-25","Type":"Other","Title":"Published"},{"CveYear":"2001","CveId":"1246","Ordinal":"3","NoteData":"2010-01-21","Type":"Other","Title":"Modified"}]}}}