CVE-2006-1014 - CERT CVE
ID CVE-2006-1014
Sažetak Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.
Reference
CVSS
Base: 3.2
Impact: 4.9
Exploitability:3.1
Pristup
VektorSloženostAutentikacija
LOCAL LOW SINGLE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL PARTIAL NONE
CVSS vektor AV:L/AC:L/Au:S/C:P/I:P/A:N
Zadnje važnije ažuriranje 18-10-2018 - 16:30
Objavljeno 07-03-2006 - 00:02