Back

CVE-2002-0985

Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.

Published: Sep 24, 2002 Modified: Jun 16, 2026
CWE-88

CVSS Metrics

Affected Products (3)

Vendor Product Version
php php * ≥ 4.0
openpkg openpkg 1.1
openpkg openpkg 1.2

GitHub Security Advisory GHSA-39rv-383r-32wp

Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.95%

Top 14% most likely to be exploited

Threat Score 30.9 / 100

Data Sources

NVD EPSS GitHub