Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP mail函数注入ASCII控制字符欺骗mail头信息漏洞
Vulnerability Description
PHP是一种流行的WEB服务器端编程语言,它功能强大,简单易用,在很多Unix操作系统默认都安装了PHP, 它也可以在Windows系统下运行。 PHP的mail函数没有很好的过滤用户的输入,远程攻击者可能利用此漏洞修改邮件头信息。 PHP的mail函数没有很好的过滤用户输入的邮件字符串变量,导致用户输入的ASCII控制字符可以修改邮件信息,包括邮件头信息。
CVSS Information
N/A
Vulnerability Type
N/A