Back
CVE-2002-0985
Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.
Published: Sep 24, 2002
Modified: Jun 16, 2026
CWE-88
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| php | php | * ≥ 4.0 |
| openpkg | openpkg | 1.1 |
| openpkg | openpkg | 1.2 |
GitHub Security Advisory GHSA-39rv-383r-32wp
Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to...
References (30)
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-008.0.txt Broken Link
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000545 Broken Link
- http://marc.info/?l=bugtraq&m=103011916928204&w=2 Third Party Advisory
- http://marc.info/?l=bugtraq&m=105760591228031&w=2 Third Party Advisory
- http://www.debian.org/security/2002/dsa-168 Broken Link, Patch, Vendor Advisory
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:082 Broken Link
- http://www.novell.com/linux/security/advisories/2002_036_modphp4.html Broken Link
- http://www.osvdb.org/2111 Broken Link
- http://www.redhat.com/support/errata/RHSA-2002-213.html Broken Link, Patch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2002-214.html Broken Link
- http://www.redhat.com/support/errata/RHSA-2002-243.html Broken Link
- http://www.redhat.com/support/errata/RHSA-2002-244.html Broken Link
- http://www.redhat.com/support/errata/RHSA-2002-248.html Broken Link
- http://www.redhat.com/support/errata/RHSA-2003-159.html Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9966 Third Party Advisory, VDB Entry
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
2.95%
Top 14% most likely to be exploited
Threat Score
30.9 / 100
Data Sources
NVD
EPSS
GitHub