Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2001-1246

PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.054
EPSS Ranking 89.7%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2001-1246
  • Php » Php » Version: 4.0.5
    cpe:2.3:a:php:php:4.0.5
  • Php » Php » Version: 4.0.6
    cpe:2.3:a:php:php:4.0.6
  • Php » Php » Version: 4.0.7
    cpe:2.3:a:php:php:4.0.7
  • Php » Php » Version: 4.1.0
    cpe:2.3:a:php:php:4.1.0


Contact Us

Shodan ® - All rights reserved