Vulnerabilities
Vulnerable Software
Php:  >> Php  >> 4.0.7  Security Vulnerabilities
The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy."
CVSS Score
5.0
EPSS Score
0.057
Published
2002-09-24
move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system.
CVSS Score
5.0
EPSS Score
0.044
Published
2002-08-12
PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.
CVSS Score
7.5
EPSS Score
0.033
Published
2001-06-30


Contact Us

Shodan ® - All rights reserved