Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2002-0986

The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.057
EPSS Ranking 90.1%
CVSS Severity
CVSS v2 Score 5.0
References
Products affected by CVE-2002-0986
  • Php » Php » Version: 3.0.18
    cpe:2.3:a:php:php:3.0.18
  • Php » Php » Version: 4.0
    cpe:2.3:a:php:php:4.0
  • Php » Php » Version: 4.0.1
    cpe:2.3:a:php:php:4.0.1
  • Php » Php » Version: 4.0.2
    cpe:2.3:a:php:php:4.0.2
  • Php » Php » Version: 4.0.3
    cpe:2.3:a:php:php:4.0.3
  • Php » Php » Version: 4.0.4
    cpe:2.3:a:php:php:4.0.4
  • Php » Php » Version: 4.0.5
    cpe:2.3:a:php:php:4.0.5
  • Php » Php » Version: 4.0.6
    cpe:2.3:a:php:php:4.0.6
  • Php » Php » Version: 4.0.7
    cpe:2.3:a:php:php:4.0.7
  • Php » Php » Version: 4.1.0
    cpe:2.3:a:php:php:4.1.0
  • Php » Php » Version: 4.1.1
    cpe:2.3:a:php:php:4.1.1
  • Php » Php » Version: 4.1.2
    cpe:2.3:a:php:php:4.1.2
  • Php » Php » Version: 4.2.0
    cpe:2.3:a:php:php:4.2.0
  • Php » Php » Version: 4.2.1
    cpe:2.3:a:php:php:4.2.1
  • Php » Php » Version: 4.2.2
    cpe:2.3:a:php:php:4.2.2


Contact Us

Shodan ® - All rights reserved