{"api_version":"1","generated_at":"2026-07-23T11:07:35+00:00","cve":"CVE-2002-0985","urls":{"html":"https://cve.report/CVE-2002-0985","api":"https://cve.report/api/cve/CVE-2002-0985.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0985","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0985"},"summary":{"title":"CVE-2002-0985","description":"Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-09-24 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-88","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://marc.info/?l=bugtraq&m=103011916928204&w=2","name":"http://marc.info/?l=bugtraq&m=103011916928204&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"'PHP: Bypass safe_mode and inject ASCII control chars with mail()' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=105760591228031&w=2","name":"http://marc.info/?l=bugtraq&m=105760591228031&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"'[OpenPKG-SA-2003.032] OpenPKG Security Advisory (php)' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:082","name":"http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:082","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Mandrakesoft Security Advisories","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-008.0.txt","name":"ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-008.0.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.redhat.com/support/errata/RHSA-2003-159.html","name":"http://www.redhat.com/support/errata/RHSA-2003-159.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2002-244.html","name":"http://www.redhat.com/support/errata/RHSA-2002-244.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2002/dsa-168","name":"http://www.debian.org/security/2002/dsa-168","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch","Vendor Advisory"],"title":"Debian -- Security Information -- DSA-168-1 php","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.novell.com/linux/security/advisories/2002_036_modphp4.html","name":"http://www.novell.com/linux/security/advisories/2002_036_modphp4.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"NOVELL: Broken Link - 404 Error Pages","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000545","name":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000545","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Home - Conectiva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2002-214.html","name":"http://www.redhat.com/support/errata/RHSA-2002-214.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2002-248.html","name":"http://www.redhat.com/support/errata/RHSA-2002-248.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/9966","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/9966","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/2111","name":"http://www.osvdb.org/2111","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.redhat.com/support/errata/RHSA-2002-213.html","name":"http://www.redhat.com/support/errata/RHSA-2002-213.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch","Vendor Advisory"],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2002-243.html","name":"http://www.redhat.com/support/errata/RHSA-2002-243.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0985","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0985","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"985","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openpkg","cpe5":"openpkg","cpe6":"1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"985","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openpkg","cpe5":"openpkg","cpe6":"1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"985","vulnerable":"1","versionEndIncluding":"4.2.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"php","cpe5":"php","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:12:16.384Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20030707 [OpenPKG-SA-2003.032] OpenPKG Security Advisory (php)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=105760591228031&w=2"},{"name":"DSA-168","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2002/dsa-168"},{"name":"php-mail-safemode-bypass(9966)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/9966"},{"name":"20020823 PHP: Bypass safe_mode and inject ASCII control chars with mail()","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=103011916928204&w=2"},{"name":"RHSA-2002:243","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2002-243.html"},{"name":"RHSA-2003:159","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2003-159.html"},{"name":"MDKSA-2003:082","tags":["vendor-advisory","x_refsource_MANDRAKE","x_transferred"],"url":"http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:082"},{"name":"CSSA-2003-008.0","tags":["vendor-advisory","x_refsource_CALDERA","x_transferred"],"url":"ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-008.0.txt"},{"name":"SuSE-SA:2002:036","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://www.novell.com/linux/security/advisories/2002_036_modphp4.html"},{"name":"CLA-2002:545","tags":["vendor-advisory","x_refsource_CONECTIVA","x_transferred"],"url":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000545"},{"name":"RHSA-2002:213","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2002-213.html"},{"name":"RHSA-2002:248","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2002-248.html"},{"name":"RHSA-2002:244","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2002-244.html"},{"name":"2111","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/2111"},{"name":"RHSA-2002:214","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2002-214.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-08-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-11-13T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20030707 [OpenPKG-SA-2003.032] OpenPKG Security Advisory (php)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=105760591228031&w=2"},{"name":"DSA-168","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2002/dsa-168"},{"name":"php-mail-safemode-bypass(9966)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/9966"},{"name":"20020823 PHP: Bypass safe_mode and inject ASCII control chars with mail()","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=103011916928204&w=2"},{"name":"RHSA-2002:243","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2002-243.html"},{"name":"RHSA-2003:159","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2003-159.html"},{"name":"MDKSA-2003:082","tags":["vendor-advisory","x_refsource_MANDRAKE"],"url":"http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:082"},{"name":"CSSA-2003-008.0","tags":["vendor-advisory","x_refsource_CALDERA"],"url":"ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-008.0.txt"},{"name":"SuSE-SA:2002:036","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://www.novell.com/linux/security/advisories/2002_036_modphp4.html"},{"name":"CLA-2002:545","tags":["vendor-advisory","x_refsource_CONECTIVA"],"url":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000545"},{"name":"RHSA-2002:213","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2002-213.html"},{"name":"RHSA-2002:248","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2002-248.html"},{"name":"RHSA-2002:244","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2002-244.html"},{"name":"2111","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/2111"},{"name":"RHSA-2002:214","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2002-214.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0985","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20030707 [OpenPKG-SA-2003.032] OpenPKG Security Advisory (php)","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=105760591228031&w=2"},{"name":"DSA-168","refsource":"DEBIAN","url":"http://www.debian.org/security/2002/dsa-168"},{"name":"php-mail-safemode-bypass(9966)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/9966"},{"name":"20020823 PHP: Bypass safe_mode and inject ASCII control chars with mail()","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=103011916928204&w=2"},{"name":"RHSA-2002:243","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2002-243.html"},{"name":"RHSA-2003:159","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2003-159.html"},{"name":"MDKSA-2003:082","refsource":"MANDRAKE","url":"http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:082"},{"name":"CSSA-2003-008.0","refsource":"CALDERA","url":"ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-008.0.txt"},{"name":"SuSE-SA:2002:036","refsource":"SUSE","url":"http://www.novell.com/linux/security/advisories/2002_036_modphp4.html"},{"name":"CLA-2002:545","refsource":"CONECTIVA","url":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000545"},{"name":"RHSA-2002:213","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2002-213.html"},{"name":"RHSA-2002:248","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2002-248.html"},{"name":"RHSA-2002:244","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2002-244.html"},{"name":"2111","refsource":"OSVDB","url":"http://www.osvdb.org/2111"},{"name":"RHSA-2002:214","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2002-214.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0985","datePublished":"2004-09-01T04:00:00.000Z","dateReserved":"2002-08-23T00:00:00.000Z","dateUpdated":"2024-08-08T03:12:16.384Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-09-24 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-88","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndIncluding":"4.2.2","matchCriteriaId":"E7CF9839-3A11-4934-B956-B590261FDAFC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openpkg:openpkg:1.1:*:*:*:*:*:*:*","matchCriteriaId":"85CCF640-211C-4EC0-9F41-68F5B39CA3F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:openpkg:openpkg:1.2:*:*:*:*:*:*:*","matchCriteriaId":"B6ADD463-E918-4F4D-9FA7-D109EBC98BD8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"985","Ordinal":"1","Title":"CVE-2002-0985","CVE":"CVE-2002-0985","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"985","Ordinal":"1","NoteData":"Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.","Type":"Description","Title":"CVE-2002-0985"},{"CveYear":"2002","CveId":"985","Ordinal":"2","NoteData":"2004-09-01","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"985","Ordinal":"3","NoteData":"2007-11-12","Type":"Other","Title":"Modified"}]}}}